PT-2026-22200 · Umbraco · Umbraco Engage

Amalie-Woern

·

Publicado

2026-02-26

·

Atualizado

2026-03-03

·

CVE-2026-27449

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Umbraco Engage versions prior to 16.2.1 Umbraco Engage versions prior to 17.1.1
Description Umbraco Engage is a business intelligence platform. A security issue exists in Umbraco Engage where certain API endpoints lack proper authentication or authorization checks. These endpoints can be accessed directly over the network without valid user credentials. An attacker can retrieve sensitive data associated with arbitrary records by supplying a user-controlled identifier parameter, such as id. The lack of access control allows for enumeration attacks, enabling attackers to extract data at scale. The exposed data may include analytics data, tracking data, and customer-related information. The confidentiality impact is considered high.
Recommendations Update to Umbraco Engage version 16.2.1. Update to Umbraco Engage version 17.1.1.

Correção

Improper Access Control

IDOR

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27449
GHSA-86VQ-CCWF-RM62

Produtos afetados

Umbraco Engage