Open redirect in Umbraco CMS - CVE-2026-46616
Published: May 16, 2026 / Updated: May 16, 2026
Umbraco CMS
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect users to an arbitrary site.
The vulnerability exists due to improper input validation in Surface Controllers when handling member-related form submissions that use a user-controlled RedirectUrl query parameter. A remote attacker can supply a crafted redirect URL to redirect users to an arbitrary site.
User interaction is required to follow the malicious redirect.