
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32818 is a Missing Authorization vulnerability in the forum module of Admidio, an open-source user management solution. It affects versions 5.0.0 through 5.0.6, allowing any authenticated user with forum access to permanently delete any forum topic (including all associated posts) or any individual post by supplying its UUID. The vulnerability was published on March 19, 2026, and patched in version 5.0.7 released March 15, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is CWE-862 (Missing Authorization): the topic_delete and post_delete action handlers in modules/forum.php validate only the CSRF token before invoking delete(), but perform no authorization check to verify whether the requesting user is a forum administrator or the content owner. This is inconsistent with the save/edit operations, which correctly call isAdministratorForum() and check post ownership via fop_usr_id_create before allowing modifications. The only pre-existing gate is a module-level check confirming the user is logged in — it does not enforce role-based or ownership-based access control. Topic UUIDs are publicly visible in page URLs, making target discovery trivial for any authenticated user (GitHub Advisory).
Any authenticated Admidio user with forum access can permanently and irreversibly delete any forum topic (cascading to all its posts) or any individual post across the platform, regardless of who created it. There is no soft-delete or trash mechanism, so recovery requires restoring from database backups. The impact is limited to integrity loss — no confidentiality breach or availability disruption beyond content destruction — but the permanent nature of the deletion and the low barrier to exploitation make this a significant data integrity risk for community-facing Admidio deployments (GitHub Advisory).
A proof-of-concept exploit consisting of concrete curl commands is publicly available in the GitHub Security Advisory, demonstrating the full attack sequence against a real Admidio deployment. The attack requires only a valid authenticated session and a CSRF token — both obtainable by any registered user — along with a target UUID visible in forum URLs. There is no evidence of in-the-wild exploitation at this time. The EPSS score is 0.026% (very low), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
?topic_uuid=<UUID>) and are not secret.adm_csrf_token value from the HTML form or a prior POST response.curl -X POST "https://TARGET/adm_program/modules/forum.php?mode=topic_delete&topic_uuid=<TOPIC_UUID>" \
-H "Cookie: ADMIDIO_SESSION_ID=<SESSION_ID>" \
-d "adm_csrf_token=<CSRF_TOKEN>"Expected response: {"status":"success"} — the topic and all associated posts are permanently deleted.
5. Delete an individual post: Send a similar POST request targeting mode=post_delete&post_uuid=<POST_UUID> with the same session and CSRF token.
6. Repeat: Iterate over any discoverable UUIDs to destroy forum content at scale (GitHub Advisory).
/adm_program/modules/forum.php with mode=topic_delete or mode=post_delete parameters originating from non-administrative user sessions; high volume of such requests in a short timeframe.{"status":"success"} responses for delete operations performed by non-admin accounts.Upgrade Admidio to version 5.0.7 or later, which adds proper authorization checks (isEditable() for topics and isAdministratorForum() / ownership checks for posts) to the delete handlers in forum.php. As a temporary workaround, restrict forum access to trusted users only by adjusting the forum_module_enabled setting or limiting forum membership. Administrators should also review forum audit logs and database backups for unauthorized deletion activity on instances running versions 5.0.0 through 5.0.6 (GitHub Advisory, Admidio Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."