CVE-2026-32817: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-32817 is a Missing Authorization and CSRF Protection vulnerability in Admidio's documents and files module that allows unauthenticated attackers to permanently delete folders and files via plain HTTP GET requests. It affects Admidio versions 5.0.0 through 5.0.6 and was published on March 20, 2026, with a fix released in version 5.0.7. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory).

Technical details

The root cause is CWE-862 (Missing Authorization): the folder_delete and file_delete action handlers in modules/documents-files.php only perform a VIEW-level authorization check (getFolderForDownload / getFileForDownload) before invoking the destructive delete() method, and they never validate a CSRF token. Target UUIDs are read directly from $_GET parameters, meaning any HTTP GET request — including one triggered by an embedded image tag — can invoke deletion. When documents_files_module_enabled = 1 (public mode) and a folder has fol_public = true, the getFolderForDownload function returns true without any login, granting unauthenticated access to the delete path. In contrast, all other write operations in the module route through DocumentsService, which properly validates CSRF tokens via getFormObject($_POST['adm_csrf_token']) — the delete handlers bypass this service entirely (GitHub Advisory).

Impact

In public mode with publicly marked folders, an unauthenticated remote attacker can permanently destroy the entire document library of an organization with a single GET request, since Folder::delete() recursively removes all sub-folders and files from both the database and the physical filesystem with no soft-delete or recovery mechanism. Even when the module is restricted to authenticated members only, any user with view-only access can delete content they are not permitted to modify, effectively escalating their privileges from read to delete. Additionally, because deletion is triggered by a GET request with no token, attackers can embed CSRF payloads in phishing emails or web pages to trigger deletion on behalf of any logged-in victim. There is no confidentiality impact, but integrity and availability impacts are both rated High (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, including concrete curl commands and a GET-based CSRF image tag payload that can trigger unauthenticated data destruction on a real target system (GitHub Advisory). The EPSS score is 0.051% (0.000510), indicating a currently low probability of widespread exploitation. No in-the-wild exploitation or threat actor attribution has been reported at this time, and the vulnerability is not listed in the CISA KEV catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify Admidio instances running versions 5.0.0–5.0.6 using search engines or web scanners. Check whether the documents module is publicly accessible by fetching https://TARGET/adm_program/modules/documents-files.php?mode=list without credentials.
  2. Enumerate folder/file UUIDs: Parse the public document listing response to extract folder and file UUIDs exposed in page URLs or JSON responses.
  3. Trigger unauthenticated folder deletion (public mode): Send a plain HTTP GET request with the target folder UUID:
    curl "https://TARGET/adm_program/modules/documents-files.php?mode=folder_delete&folder_uuid=<FOLDER_UUID>"
    Expected response: {"status":"success"}. The folder, all sub-folders, and all files are permanently deleted.
  4. Trigger authenticated view-only deletion (members-only mode): If the module requires login, authenticate as a low-privilege member and send:
    curl "https://TARGET/adm_program/modules/documents-files.php?mode=file_delete&file_uuid=<FILE_UUID>" \
      -H "Cookie: ADMIDIO_SESSION_ID=<SESSION_COOKIE>"
  5. GET-based CSRF attack: Embed an image tag in a phishing email or web page to trigger deletion on behalf of any logged-in victim who views the content:
    <img src="https://TARGET/adm_program/modules/documents-files.php?mode=folder_delete&folder_uuid=<FOLDER_UUID>">
    The victim's browser automatically sends the request with their session cookie attached (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP GET requests to /adm_program/modules/documents-files.php with mode=folder_delete or mode=file_delete parameters from unauthenticated or low-privilege sessions; requests originating from unusual IP addresses or user agents (e.g., curl).
  • Logs: Web server access logs showing GET requests to the documents-files module with folder_uuid or file_uuid parameters returning HTTP 200 with {"status":"success"} responses; repeated deletion requests in a short time window.
  • File System: Sudden disappearance of files and directories under the Admidio documents/files storage path; absence of expected document library content on disk.
  • Database: Missing records in Admidio's folder and file tables (adm_folders, adm_files) without corresponding admin activity in audit logs (GitHub Advisory).

Mitigation and workarounds

Upgrade Admidio to version 5.0.7 or later, which adds proper authorization checks and CSRF token validation to both folder_delete and file_delete handlers. If immediate patching is not possible, disable the documents and files module entirely (set documents_files_module_enabled = 0) or switch it to members-only mode (= 2) and ensure no sensitive folders are marked public. Additionally, restrict network access to the Admidio instance to trusted users until the patch is applied (GitHub Advisory).

Community reactions

The Hacker Wire published coverage of the vulnerability highlighting the critical unauthorized deletion risk in Admidio 5.0.0–5.0.6 (The Hacker Wire). The advisory was published by the Admidio maintainer (Fasse) on GitHub on March 15, 2026, with a detailed technical breakdown and recommended code fixes (GitHub Advisory). No significant broader community or social media discussion has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management