PT-2026-24485 · Umbraco · Umbraco

Odgrso

·

Publicado

2026-03-10

·

Atualizado

2026-03-11

·

CVE-2026-31832

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Umbraco versions 14.0.0 through 16.5.0 Umbraco version 17.2.2
Description Umbraco, an ASP.NET CMS, contains a flaw in a backoffice API endpoint related to object-level authorization. Authenticated users can assign domain-related data to content nodes without sufficient authorization checks. This occurs because of inadequate authorization enforcement on the API endpoint, allowing users to set domains on content nodes they are not permitted to access, either through user group privileges or start nodes. The vulnerable API endpoint allows this unauthorized assignment. The affected parameters or variables are not specified.
Recommendations Update to Umbraco version 16.5.1 or later. Update to Umbraco version 17.2.2.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-31832
GHSA-FPVF-FVP5-996R

Produtos afetados

Umbraco