Information Exposure Through an Error Message in Umbraco CMS - CVE-2025-66625

 

Information Exposure Through an Error Message in Umbraco CMS - CVE-2025-66625

Published: December 9, 2025


Vulnerability identifier: #VU119398
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-66625
CWE-ID: CWE-209
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to unsafe handling and deletion of temporary files during the dictionary upload process. A remote user can enumerate existing files on the system and under certain circumstances obtain the NTLM hash of the Windows account running the Umbraco application.


Affected software

Umbraco CMS

How to mitigate CVE-2025-66625

Install updates from vendor's website.

Umbraco CMS - update to 13.12.1

External References

Related Security Bulletins