Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-82657: Admidio before 5.0.12 lets anyone read private posts
CVE-2026-82657 · published 4 days ago
Summary
The Admidio web tool (versions older than 5.0.12) does not properly block public access to its RSS feeds for forum topics and announcements. As a result, anyone on the internet can view the titles, full text, author names, and dates of these posts without logging in. Upgrade to version 5.0.12 or later, or apply the vendor’s recommended fix, to protect this information.
What to do
- Update admidio admidio to version 5.0.12 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| admidio | admidio | < 5.0.12 |
Original advisory text
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcement...
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titles, full post text, author names, and timestamps.
References
Severity
8.7
High
CVSS 3.1: 7.5 (MITRE)
Exploitation
EPSS <1%
Type
CWE-200Information Exposure
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen30 Aug 2026
Monitor software like this
Free during beta