Authorization bypass through user-controlled key in Umbraco CMS - #VU153366

 

Authorization bypass through user-controlled key in Umbraco CMS - #VU153366

Published: October 6, 2026


Vulnerability identifier: #VU153366
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to view restricted content.

The vulnerability exists due to incomplete content-specific authorization checks in the back-office document version endpoints when handling content version requests. A remote user can request versions of content outside their assigned content tree areas to view restricted content.

Exploitation requires a valid back-office account with access to the Content section. Exposed content may include unpublished content. Media and members are not affected.


Affected software

Umbraco CMS

Remediation

Install security update from vendor's website.

Umbraco CMS - addressed in versions 17.7.1, 18.2.1

External References

Related Security Bulletins