CVE-2026-34384: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-34384 is a Cross-Site Request Forgery (CSRF) vulnerability in Admidio, an open-source user management solution, affecting all versions prior to 5.0.8. The flaw exists in modules/registration.php, where the create_user, assign_member, and assign_user action modes approve pending user registrations via GET requests without validating a CSRF token. It was published on March 31, 2026, with a patch released in version 5.0.8. The CVSS v3.1 base score is 7.3 (High) per Feedly/NVD, while the GitHub Advisory Database rates it 4.5 (Moderate) (Github Advisory, Feedly).

Technical details

The root cause is CWE-352 (Cross-Site Request Forgery): the three registration approval action modes (create_user, assign_member, assign_user) in modules/registration.php read parameters exclusively from $_GET and perform irreversible state changes without any CSRF token validation. By contrast, the delete_user mode in the same file correctly calls SecurityUtils::validateCsrfToken($_POST['adm_csrf_token']). Because the attacker's own user UUID is embedded in the registration confirmation email URL (https://TARGET/adm_program/modules/registration.php?id=VALIDATION_ID&user_uuid=REGISTRANT_UUID), the attacker already possesses the required parameter. Exploitation requires only that a user holding the rol_approve_users right (a common delegated privilege, not full admin) visit a crafted URL or load a page containing a hidden image tag pointing to the malicious endpoint — no JavaScript is required (Github Advisory, Patch Commit).

Impact

Successful exploitation has two primary consequences: (1) Manual approval bypass — an attacker with a pending registration can silently auto-approve their own account, gaining organization membership and access to role-restricted resources such as events, documents, and mailing lists without administrative review; and (2) Account takeover via assign_user CSRF — if the attacker can obtain any existing member's UUID (visible in profile page URLs on installations with a public user list), the assign_user mode merges the attacker's pending registration into that member's account, replacing the victim's login credentials with the attacker's. This results in a full account takeover with high integrity impact and potential confidentiality exposure through the hijacked account (Github Advisory).

Exploitability

A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, consisting of a concrete HTML payload (an <img> tag with a crafted URL) that triggers silent registration approval when loaded by a victim with rol_approve_users rights. No exploit kits or in-the-wild exploitation have been observed as of the advisory date. The EPSS score is approximately 0.013% (0.000130), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog (Github Advisory, Feedly).

Exploitation steps

  1. Register an account: The attacker submits a registration form on the target Admidio instance with manual approval enabled, then clicks the confirmation link in the received email to place the registration in the pending queue.
  2. Extract attacker UUID: The attacker retrieves their own user_uuid from the registration confirmation email URL: https://TARGET/adm_program/modules/registration.php?id=VALIDATION_ID&user_uuid=ATTACKER_UUID.
  3. Craft the CSRF payload: The attacker creates a malicious HTML page containing an image tag that silently triggers the approval endpoint:
<img src="https://TARGET/adm_program/modules/registration.php?mode=create_user&user_uuid=ATTACKER_UUID" width="1" height="1">
  1. Deliver the payload: The attacker tricks a user with the rol_approve_users right (e.g., a membership secretary) into visiting the malicious page via phishing, a forum post, or an embedded link.
  2. Auto-approval achieved: When the victim's browser loads the page, it sends an authenticated GET request to the Admidio endpoint, which approves the attacker's registration without any CSRF token check, granting the attacker organization membership.
  3. (Optional) Account takeover: If the attacker can obtain an existing member's UUID from public profile URLs, they substitute it as user_uuid_assigned and use mode=assign_user to merge their pending registration into the victim account, replacing that account's credentials (Github Advisory).

Indicators of compromise

  • Network: Unexpected GET requests to /adm_program/modules/registration.php with parameters mode=create_user, mode=assign_member, or mode=assign_user originating from unusual referrers (e.g., external domains, image-loading contexts) in web server access logs.
  • Logs: Web server access logs showing requests to the registration approval endpoints from IP addresses not associated with administrative users, or requests arriving in rapid succession without prior navigation through the admin UI.
  • Application: Newly approved user accounts in Admidio that were approved without a corresponding administrator session activity, or accounts whose registration approval timestamp does not align with known admin login sessions.
  • Application: Existing member accounts with recently changed login credentials or merged registrations, particularly if the account owner did not initiate the change — indicative of the assign_user account takeover variant (Github Advisory).

Mitigation and workarounds

Upgrade Admidio to version 5.0.8 or later, which adds SecurityUtils::validateCsrfToken($_POST['adm_csrf_token']) at the start of the create_user, assign_member, and assign_user action modes, and converts approval buttons to POST-form submissions with CSRF tokens in hidden fields — consistent with the existing delete_user protection (Patch Commit). No official configuration-based workaround is available for unpatched versions; as a temporary measure, administrators could disable public registration or restrict network access to the registration module until patching is feasible. Organizations should also audit recently approved accounts for unauthorized approvals (Github Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management