PT-2026-24485 · Umbraco · Umbraco
Odgrso
·
Publicado
2026-03-10
·
Atualizado
2026-03-11
·
CVE-2026-31832
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Umbraco versions 14.0.0 through 16.5.0
Umbraco version 17.2.2
Description
Umbraco, an ASP.NET CMS, contains a flaw in a backoffice API endpoint related to object-level authorization. Authenticated users can assign domain-related data to content nodes without sufficient authorization checks. This occurs because of inadequate authorization enforcement on the API endpoint, allowing users to set domains on content nodes they are not permitted to access, either through user group privileges or start nodes. The vulnerable API endpoint allows this unauthorized assignment. The affected parameters or variables are not specified.
Recommendations
Update to Umbraco version 16.5.1 or later.
Update to Umbraco version 17.2.2.
Exploit
Correção
IDOR
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Umbraco