
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34384 is a Cross-Site Request Forgery (CSRF) vulnerability in Admidio, an open-source user management solution, affecting all versions prior to 5.0.8. The flaw exists in modules/registration.php, where the create_user, assign_member, and assign_user action modes approve pending user registrations via GET requests without validating a CSRF token. It was published on March 31, 2026, with a patch released in version 5.0.8. The CVSS v3.1 base score is 7.3 (High) per Feedly/NVD, while the GitHub Advisory Database rates it 4.5 (Moderate) (Github Advisory, Feedly).
The root cause is CWE-352 (Cross-Site Request Forgery): the three registration approval action modes (create_user, assign_member, assign_user) in modules/registration.php read parameters exclusively from $_GET and perform irreversible state changes without any CSRF token validation. By contrast, the delete_user mode in the same file correctly calls SecurityUtils::validateCsrfToken($_POST['adm_csrf_token']). Because the attacker's own user UUID is embedded in the registration confirmation email URL (https://TARGET/adm_program/modules/registration.php?id=VALIDATION_ID&user_uuid=REGISTRANT_UUID), the attacker already possesses the required parameter. Exploitation requires only that a user holding the rol_approve_users right (a common delegated privilege, not full admin) visit a crafted URL or load a page containing a hidden image tag pointing to the malicious endpoint — no JavaScript is required (Github Advisory, Patch Commit).
Successful exploitation has two primary consequences: (1) Manual approval bypass — an attacker with a pending registration can silently auto-approve their own account, gaining organization membership and access to role-restricted resources such as events, documents, and mailing lists without administrative review; and (2) Account takeover via assign_user CSRF — if the attacker can obtain any existing member's UUID (visible in profile page URLs on installations with a public user list), the assign_user mode merges the attacker's pending registration into that member's account, replacing the victim's login credentials with the attacker's. This results in a full account takeover with high integrity impact and potential confidentiality exposure through the hijacked account (Github Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, consisting of a concrete HTML payload (an <img> tag with a crafted URL) that triggers silent registration approval when loaded by a victim with rol_approve_users rights. No exploit kits or in-the-wild exploitation have been observed as of the advisory date. The EPSS score is approximately 0.013% (0.000130), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog (Github Advisory, Feedly).
user_uuid from the registration confirmation email URL: https://TARGET/adm_program/modules/registration.php?id=VALIDATION_ID&user_uuid=ATTACKER_UUID.<img src="https://TARGET/adm_program/modules/registration.php?mode=create_user&user_uuid=ATTACKER_UUID" width="1" height="1">rol_approve_users right (e.g., a membership secretary) into visiting the malicious page via phishing, a forum post, or an embedded link.user_uuid_assigned and use mode=assign_user to merge their pending registration into the victim account, replacing that account's credentials (Github Advisory)./adm_program/modules/registration.php with parameters mode=create_user, mode=assign_member, or mode=assign_user originating from unusual referrers (e.g., external domains, image-loading contexts) in web server access logs.assign_user account takeover variant (Github Advisory).Upgrade Admidio to version 5.0.8 or later, which adds SecurityUtils::validateCsrfToken($_POST['adm_csrf_token']) at the start of the create_user, assign_member, and assign_user action modes, and converts approval buttons to POST-form submissions with CSRF tokens in hidden fields — consistent with the existing delete_user protection (Patch Commit). No official configuration-based workaround is available for unpatched versions; as a temporary measure, administrators could disable public registration or restrict network access to the registration module until patching is feasible. Organizations should also audit recently approved accounts for unauthorized approvals (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."