
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34382 is a Cross-Site Request Forgery (CSRF) vulnerability in Admidio, an open-source user management solution, affecting the delete mode handler in modules/groups-roles/mylist_function.php. Versions 5.0.0 through 5.0.7 are affected; the issue was patched in version 5.0.8. Discovered and reported by Juan Felipe Oz (@JF0x0r), the advisory was published on March 27, 2026, and assigned a CVE on March 31, 2026. It carries a CVSS v3.1 base score of 4.6 (Medium) (Github Advisory, Admidio Advisory).
The root cause is CWE-352 (Cross-Site Request Forgery): the delete mode branch in mylist_function.php (lines 159–161) executes a permanent list deletion ($list->delete()) without validating an adm_csrf_token. While CSRF token validation was correctly implemented for the save, save_as, and save_temporary modes (lines 81–82), it was entirely absent for the delete mode. A global input guard requiring a non-empty column[] POST parameter exists but provides no real security barrier, as any trivial value (e.g., LAST_NAME) satisfies it. An attacker must know the target list's UUID (visible in the page URL at modules/groups-roles/mylist.php?list_uuid=...) and trick an authenticated user into visiting a malicious page that auto-submits a crafted HTML form (Admidio Advisory, Github Advisory).
Successful exploitation allows an attacker to permanently and silently delete any list configuration accessible to the authenticated victim, with no soft-delete or recovery mechanism available. When the victim holds administrator rights, all six organization-wide shared lists (Address list, Phone list, Contact information, Membership, Members, and Contacts) can be destroyed, disrupting operations for all members of the organization. There is no confidentiality impact, but integrity and availability are both degraded through irreversible data loss (Admidio Advisory).
A public proof-of-concept (PoC) exploit is available in the official security advisory, consisting of a crafted HTML form with auto-submit JavaScript that triggers the vulnerable endpoint without a CSRF token. The EPSS score is approximately 0.015% (1st percentile), and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory, Admidio Advisory).
modules/groups-roles/mylist.php?list_uuid=<TARGET_UUID> (requires some level of access or social engineering to obtain).<form id="f" method="POST" action="http://TARGET/modules/groups-roles/mylist_function.php?mode=delete&list_uuid=TARGET_UUID">
<input type="hidden" name="column[]" value="LAST_NAME">
</form>
<script>document.getElementById('f').submit();</script>{"status":"success",...}.SELECT lst_name FROM adm_lists WHERE lst_uuid='TARGET_UUID'; returns an empty result set (Admidio Advisory)./modules/groups-roles/mylist_function.php?mode=delete&list_uuid=<UUID> originating from unusual referrer domains or with no referrer header; requests containing column[]=LAST_NAME (or similar trivial values) in the body alongside a mode=delete parameter.mylist_function.php with mode=delete from IP addresses or referrers inconsistent with normal user activity; JSON success responses ({"status":"success"}) returned for delete operations.adm_lists table, particularly organization-wide shared lists (lst_global = 1) such as Address list, Phone list, Contact information, Membership, Members, or Contacts; absence of corresponding user-initiated delete actions in application audit logs.Upgrade Admidio to version 5.0.8 or later, which moves the CSRF token validation check to a global position (lines 41–45) covering all modes including delete, as implemented in commit 317ec91 (Patch Commit). As a defense-in-depth measure, configure session cookies with the SameSite=Strict or SameSite=Lax attribute to reduce CSRF attack surface. Until patching is possible, restrict access to the Admidio instance to trusted networks and educate users — especially administrators — to avoid clicking untrusted links while authenticated (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."