Missing Authorization in Umbraco CMS - CVE-2026-31834
Published: May 5, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to missing authorization in user group membership management functionality when modifying user group memberships. A remote privileged user can assign highly privileged roles to escalate privileges.
Exploitation requires access to the "Users" section in the backoffice.