SB2025120920 - Information disclosure in Umbraco CMS
Published: December 9, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information Exposure Through an Error Message (CVE-ID: CVE-2025-66625)
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to unsafe handling and deletion of temporary files during the dictionary upload process. A remote user can enumerate existing files on the system and under certain circumstances obtain the NTLM hash of the Windows account running the Umbraco application.
Remediation
Install update from vendor's website.