<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T13:23:57.203119+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-309012</id>
    <title>EUVD-2026-309012</title>
    <updated>2026-10-07T13:23:57.252358+00:00</updated>
    <content>EUVD-2026-309012</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-309012"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41662</id>
    <title>fkie_cve-2026-41662</title>
    <updated>2026-10-07T13:23:57.252398+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify whether removing a user from the administrator role leaves zero administrators. The deprecated Membership::stopMembership() contains this safety check, but the current code path bypasses it. Any administrator can remove the last remaining other administrator, locking the entire system out of administrative access. The exploit does not require concurrent requests; sequential removals produce the same result. This issue has been patched in version 5.0.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-41662"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c7xm-r6vj-8vg6</id>
    <title>GHSA-c7xm-r6vj-8vg6 — Admidio Missing Minimum Administrator Check in Role Membership Removal</title>
    <updated>2026-10-07T13:23:57.252432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: admidio/admidio</p>
<p>## Summary</p>
<p>`Role::stopMembership()` does not verify whether removing a user from the administrator role leaves zero administrators. The deprecated `Membership::stopMembership()` contains this safety check, but the current code path bypasses it. Any administrator can remove the last remaining other administrator, locking the entire system out of administrative access. The exploit does not require concurrent requests; sequential removals produce the same result.</p>
<p>## Details</p>
<p>`Role::stopMembership()` in `src/Roles/Entity/Role.php` stops a user's membership in a role without verifying whether the action leaves the administrator role with zero members:</p>
<p>```php
// src/Roles/Entity/Role.php - Role::stopMembership()
public function stopMembership(int $userId): bool
{
    // No check for minimum administrator count
    // Directly updates membership end date
}
```</p>
<p>The deprecated `Membership::stopMembership()` contains this safety check and raises `SYS_MUST_HAVE_ADMINISTRATOR` when the removal would leave no admins, but current code paths no longer call this method.</p>
<p>`Role::setMembership()` includes a guard that prevents a user from removing their own administrator membership:</p>
<p>```php
if ($userId === $gCurrentUserId) {
    // Prevents self-removal from admin role
}
```</p>
<p>This guard does not prevent an administrator from removing the last other administrator. Consider a system with exactly two administrators (Admin A and Admin B):</p>
<p>1. Admin A removes Admin B from the administrator rol…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c7xm-r6vj-8vg6"/>
  </entry>
</feed>
