CVE-2026-30927: Admidio: Event participation IDOR - non-leaders can register other users for events via user_uuid parameter
(updated )
- Register unwilling users for events (potential harassment/spam)
- Cancel other users’ event participation
- Manipulate event participant counts and comments
- If events have participation limits, fill slots with unwanted registrations
References
Code Behaviors & Features
Detect and mitigate CVE-2026-30927 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →