CVE-2026-34382: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34382 is a Cross-Site Request Forgery (CSRF) vulnerability in Admidio, an open-source user management solution, affecting the delete mode handler in modules/groups-roles/mylist_function.php. Versions 5.0.0 through 5.0.7 are affected; the issue was patched in version 5.0.8. Discovered and reported by Juan Felipe Oz (@JF0x0r), the advisory was published on March 27, 2026, and assigned a CVE on March 31, 2026. It carries a CVSS v3.1 base score of 4.6 (Medium) (Github Advisory, Admidio Advisory).

Technical details

The root cause is CWE-352 (Cross-Site Request Forgery): the delete mode branch in mylist_function.php (lines 159–161) executes a permanent list deletion ($list->delete()) without validating an adm_csrf_token. While CSRF token validation was correctly implemented for the save, save_as, and save_temporary modes (lines 81–82), it was entirely absent for the delete mode. A global input guard requiring a non-empty column[] POST parameter exists but provides no real security barrier, as any trivial value (e.g., LAST_NAME) satisfies it. An attacker must know the target list's UUID (visible in the page URL at modules/groups-roles/mylist.php?list_uuid=...) and trick an authenticated user into visiting a malicious page that auto-submits a crafted HTML form (Admidio Advisory, Github Advisory).

Impact

Successful exploitation allows an attacker to permanently and silently delete any list configuration accessible to the authenticated victim, with no soft-delete or recovery mechanism available. When the victim holds administrator rights, all six organization-wide shared lists (Address list, Phone list, Contact information, Membership, Members, and Contacts) can be destroyed, disrupting operations for all members of the organization. There is no confidentiality impact, but integrity and availability are both degraded through irreversible data loss (Admidio Advisory).

Exploitability

A public proof-of-concept (PoC) exploit is available in the official security advisory, consisting of a crafted HTML form with auto-submit JavaScript that triggers the vulnerable endpoint without a CSRF token. The EPSS score is approximately 0.015% (1st percentile), and there is no evidence of active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Github Advisory, Admidio Advisory).

Exploitation steps

  1. Reconnaissance: Identify a target Admidio instance running versions 5.0.0–5.0.7. Obtain the UUID of the target list by observing the URL when browsing modules/groups-roles/mylist.php?list_uuid=<TARGET_UUID> (requires some level of access or social engineering to obtain).
  2. Craft malicious page: Create an HTML page hosted on any HTTP origin containing an auto-submitting form targeting the vulnerable endpoint:
<form id="f" method="POST" action="http://TARGET/modules/groups-roles/mylist_function.php?mode=delete&list_uuid=TARGET_UUID">
  <input type="hidden" name="column[]" value="LAST_NAME">
</form>
<script>document.getElementById('f').submit();</script>
  1. Deliver the page: Lure an authenticated Admidio user (ideally an administrator) to visit the malicious page via phishing, a malicious link, or an embedded iframe.
  2. Trigger deletion: The victim's browser automatically submits the form using their active session cookies. The server processes the request without CSRF token validation and responds with {"status":"success",...}.
  3. Confirm impact: The targeted list is permanently deleted from the database. Verification: SELECT lst_name FROM adm_lists WHERE lst_uuid='TARGET_UUID'; returns an empty result set (Admidio Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /modules/groups-roles/mylist_function.php?mode=delete&list_uuid=<UUID> originating from unusual referrer domains or with no referrer header; requests containing column[]=LAST_NAME (or similar trivial values) in the body alongside a mode=delete parameter.
  • Logs: Web server access logs showing POST requests to mylist_function.php with mode=delete from IP addresses or referrers inconsistent with normal user activity; JSON success responses ({"status":"success"}) returned for delete operations.
  • Application/Database: Sudden disappearance of list configurations from the adm_lists table, particularly organization-wide shared lists (lst_global = 1) such as Address list, Phone list, Contact information, Membership, Members, or Contacts; absence of corresponding user-initiated delete actions in application audit logs.

Mitigation and workarounds

Upgrade Admidio to version 5.0.8 or later, which moves the CSRF token validation check to a global position (lines 41–45) covering all modes including delete, as implemented in commit 317ec91 (Patch Commit). As a defense-in-depth measure, configure session cookies with the SameSite=Strict or SameSite=Lax attribute to reduce CSRF attack surface. Until patching is possible, restrict access to the Admidio instance to trusted networks and educate users — especially administrators — to avoid clicking untrusted links while authenticated (Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management