diff --git a/core/ajax/appconfig.php b/core/ajax/appconfig.php
index f815d710631f81a1ccf6a50acf391f77cc13b199..de91d458ed153286ee1828d7ca5e877728d35214 100644
--- a/core/ajax/appconfig.php
+++ b/core/ajax/appconfig.php
@@ -6,6 +6,7 @@
  */
 
 require_once ("../../lib/base.php");
+OC_Util::checkAdminUser();
 OC_JSON::checkLoggedIn();
 $action=isset($_POST['action'])?$_POST['action']:$_GET['action'];
 $result=false;