CVE-2026-47234

MEDIUM CVSS 3.1: 4.4
Updated Aug 12, 2026
Admidio
Parameter Value
CVSS 4.4 (MEDIUM)
Type CWE-200 (Information Exposure), CWE-532
Vendor Admidio
Public PoC No

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment this includes both the active session cookie and the persistent auto-login cookie.

Anyone with access to the log sink can recover live bearer-style credentials from the logs. Version 5.0.10 contains a fix.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1