SB2026100656 - Multiple vulnerabilities in Umbraco CMS
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to delete media files outside their authorized media library scope.
The vulnerability exists due to improper access control in Backoffice media management when handling media operations. A remote user can perform media operations affecting files outside their permitted start node to delete media files outside their authorized media library scope.
Exploitation requires a Backoffice account with access to the Media section.
2) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to view restricted content.
The vulnerability exists due to incomplete content-specific authorization checks in the back-office document version endpoints when handling content version requests. A remote user can request versions of content outside their assigned content tree areas to view restricted content.
Exploitation requires a valid back-office account with access to the Content section. Exposed content may include unpublished content. Media and members are not affected.
3) Missing Authentication for Critical Function (CVE-ID: N/A)
CWE-ID: CWE-306 - Missing Authentication for Critical Function
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to obtain content identifiers and editorial activity information.
The vulnerability exists due to missing authentication in back-office SignalR hubs when accepting client connections. A remote attacker can connect to the exposed endpoints and receive real-time notifications to obtain content identifiers and editorial activity information.
The activity information includes when content is created or edited, including unpublished content. Content itself, credentials and management capabilities are not exposed, and the issue does not allow content to be changed.
Remediation
Install update from vendor's website.
References
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-7pj9-jmp9-p86q
- https://github.com/umbraco/Umbraco-CMS/releases/tag/release-18.2.1
- https://github.com/umbraco/Umbraco-CMS/releases/tag/release-17.7.1
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-w5jr-cmfx-544x
- https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-4c5q-6c64-96j7