Authorization bypass through user-controlled key in Umbraco CMS - CVE-2026-31832
Published: May 5, 2026
Umbraco CMS
Detailed vulnerability description
The vulnerability allows a remote user to modify domain-related data for content nodes without proper authorization.
The vulnerability exists due to broken object-level authorization in a backoffice API endpoint when handling API requests to assign domains to content nodes. A remote user can send a crafted API request to modify domain-related data for content nodes without proper authorization.
This may result in malicious or unintended routing behavior, service disruption, and potential disclosure of configuration-related information.