CVE-2026-34381: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34381 is an improper access control vulnerability in Admidio, an open-source user management solution, that allows unauthenticated attackers to directly access role-restricted uploaded documents via HTTP. The vulnerability affects Admidio versions 5.0.0 through 5.0.7 when deployed using the official Docker image. It was reported by Juan Felipe Oz (@JF0x0r), published on March 27, 2026, and patched in version 5.0.8. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).

Technical details

The root cause is a misconfiguration in the Admidio Docker image's Apache configuration (CWE-284: Improper Access Control). Admidio relies on adm_my_files/.htaccess containing Require all denied to block direct HTTP access to uploaded files, but the Docker image ships with AllowOverride None in /etc/apache2/apache2.conf, which instructs Apache to silently ignore all .htaccess directives. Because the upload directory (/opt/app-root/src/adm_my_files/) resides within the web root, files are served directly with HTTP 200 responses. Compounding the issue, the upload API endpoint (system/file_upload.php) returns the full direct URL to the uploaded file in its JSON response, trivially disclosing the file path to any uploader (GitHub Advisory).

Impact

Any file uploaded to Admidio's documents module — regardless of role-based permissions configured in the UI — is publicly accessible via a direct HTTP GET request with no authentication required. This completely bypasses the role-based access control system at the filesystem level, exposing sensitive organizational documents such as contracts, member data, and financial records to any unauthenticated party who knows or can construct the file path. There is no integrity or availability impact; the vulnerability is limited to a high confidentiality impact (GitHub Advisory).

Exploitability

A verified proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating a complete 4-step attack sequence using a simple curl command to retrieve restricted files without authentication (GitHub Advisory). The EPSS score is approximately 0.054% (17th percentile), indicating a low but non-negligible probability of exploitation in the wild. No threat actor attribution or CISA KEV catalog listing has been identified at this time. The low attack complexity (no privileges, no user interaction required) and the fact that the upload response directly discloses the file URL make exploitation trivial for any attacker with network access to the target.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Admidio instances running versions 5.0.0–5.0.7 via the Docker image, using tools like Shodan or Censys searching for Admidio-specific HTTP response headers or page content.
  2. Obtain a file path: Either (a) authenticate as any user with upload privileges, upload a file to any folder, and capture the direct URL from the JSON upload response (e.g., http://TARGET/adm_my_files/documents_research/TEST-SENSITIVE/sensitive_poc.txt), or (b) attempt to guess or enumerate predictable file paths based on known Admidio folder naming conventions.
  3. Retrieve the restricted file unauthenticated: Issue a direct HTTP GET request to the disclosed file path without any session cookie or credentials:
    curl -X GET 'http://TARGET/adm_my_files/documents_research/TEST-SENSITIVE/sensitive_poc.txt'
    The server returns the full file contents with HTTP 200, bypassing all role-based access controls.
  4. Enumerate additional files: Repeat step 3 for other known or guessable paths within adm_my_files/ to harvest additional sensitive documents (GitHub Advisory).

Indicators of compromise

  • Network: Unauthenticated HTTP GET requests (no session cookie) to paths matching adm_my_files/documents_*/ returning HTTP 200 responses; unusual volume of direct file requests to the adm_my_files directory from external IPs.
  • Logs: Apache access logs showing GET requests to /adm_my_files/ paths without associated authenticated session activity; requests originating from IPs with no prior login activity in the application logs.
  • File System: Review of adm_my_files/.htaccess to confirm Require all denied is present but ineffective; Apache configuration files showing AllowOverride None without a directory-specific override for the Admidio path.
  • Application: Upload API responses (system/file_upload.php) logged with full file URLs in JSON output, indicating paths that may have been disclosed to potential attackers (GitHub Advisory).

Mitigation and workarounds

Upgrade Admidio to version 5.0.8 or later, which resolves the issue by adding a custom Apache directory configuration (admidio-custom.conf) that sets AllowOverride All for the Admidio directory, allowing .htaccess files to function as intended (Patch Commit). If immediate patching is not possible, three workarounds are available: (1) manually set AllowOverride All in the Apache configuration for the Admidio directory; (2) add an explicit Apache-level Require all denied directive for the adm_my_files directory without relying on .htaccess; or (3) move the upload directory outside the web root and serve files exclusively through Admidio's download handler (modules/documents-files.php?mode=download), which enforces role checks — this is the most robust long-term solution (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher Juan Felipe Oz (@JF0x0r) and disclosed responsibly through GitHub's security advisory process. A post on Bluesky by cyberhub.blog noted the vulnerability shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond the original advisory has been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management