SB2025120920 - Information disclosure in Umbraco CMS



SB2025120920 - Information disclosure in Umbraco CMS

Published: December 9, 2025

Security Bulletin ID SB2025120920
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information Exposure Through an Error Message (CVE-ID: CVE-2025-66625)

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to unsafe handling and deletion of temporary files during the dictionary upload process. A remote user can enumerate existing files on the system and under certain circumstances obtain the NTLM hash of the Windows account running the Umbraco application.


Remediation

Install update from vendor's website.