Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32817

30
FAUCET Score

CVE-2026-32817 is a critical improper authorization vulnerability affecting Admidio versions 5.0.0 through 5.0.6, specifically within its documents and files module. The flaw allows deletion of folders and files without proper permission checks or CSRF protection, enabling attackers to trigger deletions via simple HTTP GET requests. With a CVSS score of 9.1 (CRITICAL), this network-exploitable, low-complexity vulnerability can lead to high impact on data integrity and availability, potentially allowing unauthenticated users to destroy entire document libraries. While severe, there is currently no evidence of active exploitation, public exploit code, or significant community discussion. The issue has been resolved in Admidio version 5.0.7.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.0.0, < 5.0.7CPE matchmatch criteria
cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 4th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: admidio/admidioFixed in: 5.0.7
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-rmpj-3x5m-9m5fcritical

Admidio is Missing Authorization and CSRF Protection on Document and Folder Deletion

Mar 16, 2026

References

github.com / Admidio/admidio/security/advisories/GHSA-rmpj-3x5m-9m5f
ExploitMitigationVendor Advisory