GHSA-95cq-p4w2-32w5 · Severity: high · Ecosystem: composer — File Upload(RCE) Vulnerability in admidio
Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload vulnerability in the Documents & Files module. Due to a design flaw in how CSRF token validation and file extension verification interact within UploadHandlerFile.php, an authenticated user with upload permissions can bypass file extension restrictions by intentionally submitting an invalid CSRF token. This allows the upload of arbitrary file types, including PHP scripts, which may lead to Remote Code Execution on the server, resulting in full server compromise, data exfiltration, and lateral movement. This issue has been fixed in version 5.0.7.
Conclusion & alert: CVE-2026-32756 is rated High Exploit Risk (71.3/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.98%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.05% | 0.98% | +0.93% |
| 2 | 2026-05-26 | 0.03% | 0.05% | +0.02% |
| 3 | 2026-03-21 | — | 0.03% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
GHSA-95cq-p4w2-32w5 · Severity: high · Ecosystem: composer — File Upload(RCE) Vulnerability in admidio
| URL | Tags |
|---|---|
| https://github.com/Admidio/admidio/releases/tag/v5.0.7 | Patch Product |
| https://github.com/Admidio/admidio/security/advisories/GHSA-95cq-p4w2-32w5 | Exploit Mitigation Vendor Advisory |