PT-2026-24485 · Umbraco · Umbraco

Odgrso

·

Published

2026-03-10

·

Updated

2026-03-11

·

CVE-2026-31832

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Umbraco versions 14.0.0 through 16.5.0 Umbraco version 17.2.2
Description Umbraco, an ASP.NET CMS, contains a flaw in a backoffice API endpoint related to object-level authorization. Authenticated users can assign domain-related data to content nodes without sufficient authorization checks. This occurs because of inadequate authorization enforcement on the API endpoint, allowing users to set domains on content nodes they are not permitted to access, either through user group privileges or start nodes. The vulnerable API endpoint allows this unauthorized assignment. The affected parameters or variables are not specified.
Recommendations Update to Umbraco version 16.5.1 or later. Update to Umbraco version 17.2.2.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-31832
GHSA-FPVF-FVP5-996R

Affected Products

Umbraco