SB2023071368 - Improper access control in Umbraco CMS



SB2023071368 - Improper access control in Umbraco CMS

Published: July 13, 2023 Updated: May 5, 2026

Security Bulletin ID SB2023071368
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2023-37267)

The vulnerability allows a remote attacker to gain admin-level access to the backoffice.

The vulnerability exists due to improper access control in the backoffice installation mode when Umbraco is restarted while the database is unavailable and then the connection is re-established. A remote attacker can cause the application to boot into installation mode and reset admin credentials to gain admin-level access to the backoffice.

User interaction is required.


Remediation

Install update from vendor's website.