PT-2026-5347 · Umbraco · Umbraco Forms

Kevin Joensen

·

Publicado

2026-01-29

·

Atualizado

2026-03-02

·

CVE-2026-24687

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Umbraco Forms versions 16 through 17
Description Umbraco Forms, a form builder integrated with the Umbraco content management system, contains a flaw that allows an authenticated backoffice user to list and access files on the system's file system, and read their contents on Mac and Linux Umbraco installations. The issue affects versions 16 and 17. The /umbraco/forms/api/v1/export API endpoint is involved, and the fileName parameter is susceptible to path traversal attacks using sequences like ../ and ... Umbraco Cloud users are not affected as it runs in a Windows environment.
Recommendations Umbraco Forms version 16.4.1 Umbraco Forms version 17.1.1 If upgrading is not immediately possible, configure a WAF or reverse proxy to block requests containing path traversal sequences (../, ..) in the fileName parameter of the ''/umbraco/forms/api/v1/export'' endpoint. Restrict network access to the Umbraco backoffice to trusted IP ranges. Block the ''/umbraco/forms/api/v1/export'' endpoint entirely if the export feature is not required.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24687
GHSA-HM5P-82G6-M3XH

Produtos afetados

Umbraco Forms