{"id":"CVE-2026-41657","summary":"Admidio: Cross-Organization Member Data Exposure via Permission Check Mismatch in contacts_data.php","details":"Admidio is an open-source user management solution. Prior to version 5.0.9, the contacts_data.php endpoint uses a weaker permission check (isAdministratorUsers(), requiring only rol_edit_user=true) than the frontend UI (contacts.php) which correctly requires the stronger isAdministrator() (requiring rol_administrator=true) and the contacts_show_all system setting. A user manager who is not a full administrator can directly request contacts_data.php?mem_show_filter=3 to retrieve all user records across all organizations in the Admidio instance, bypassing multi-tenant organization isolation. This issue has been patched in version 5.0.9.","aliases":["GHSA-g8p8-94f2-28gr"],"modified":"2026-08-12T03:51:09.067754434Z","published":"2026-05-07T02:58:09.340Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41657.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-863"]},"references":[{"type":"WEB","url":"https://github.com/Admidio/admidio/releases/tag/v5.0.9"},{"type":"ADVISORY","url":"https://github.com/Admidio/admidio/security/advisories/GHSA-g8p8-94f2-28gr"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41657.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41657"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/admidio/admidio","events":[{"introduced":"0"},{"fixed":"d39915697e6e0be04d02d55a46c631f53013aea6"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.0.9"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v5.0.8","v5.0.7","v5.0.6","v5.0.5","v5.0.4","v34","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v5.0-Beta.3","v5.0-Beta.2","v5.0-Beta.1","v4.3-Beta.1","v4.1-Beta.2","v4.0-Beta.1","v3.2-Beta.1","v3.1.5","v3.0.6","3.0-Beta.3","3.0-Beta.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41657.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}