Authorization bypass through user-controlled key in Umbraco CMS - #VU153365
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to delete media files outside their authorized media library scope.
The vulnerability exists due to improper access control in Backoffice media management when handling media operations. A remote user can perform media operations affecting files outside their permitted start node to delete media files outside their authorized media library scope.
Exploitation requires a Backoffice account with access to the Media section.