Missing Authorization in Umbraco CMS - CVE-2026-31834
Published: May 5, 2026
Umbraco CMS
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to missing authorization in user group membership management functionality when modifying user group memberships. A remote privileged user can assign highly privileged roles to escalate privileges.
Exploitation requires access to the "Users" section in the backoffice.