CVE-2026-34381 affects Admidio versions 5.0.0 through 5.0.7, specifically when deployed via Docker, allowing unauthorized direct HTTP access to uploaded documents. This critical flaw arises because the Docker image's Apache configuration ignores .htaccess files, making all uploaded content publicly accessible without authentication if the file path is known. Rated 7.5 High (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), it presents a significant confidentiality risk as sensitive data can be exposed over the network with low attack complexity. There is currently no evidence of active exploitation, no public exploit code is available, and community discussion remains minimal. Organizations using affected versions should upgrade to Admidio 5.0.8 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.0.0, < 5.0.8CPE matchmatch criteria | cpe:2.3:a:admidio:admidio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.