Authorization bypass through user-controlled key in Umbraco CMS - #VU153366
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to view restricted content.
The vulnerability exists due to incomplete content-specific authorization checks in the back-office document version endpoints when handling content version requests. A remote user can request versions of content outside their assigned content tree areas to view restricted content.
Exploitation requires a valid back-office account with access to the Content section. Exposed content may include unpublished content. Media and members are not affected.