PT-2026-24485 · Umbraco · Umbraco
Odgrso
·
Published
2026-03-10
·
Updated
2026-03-11
·
CVE-2026-31832
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Umbraco versions 14.0.0 through 16.5.0
Umbraco version 17.2.2
Description
Umbraco, an ASP.NET CMS, contains a flaw in a backoffice API endpoint related to object-level authorization. Authenticated users can assign domain-related data to content nodes without sufficient authorization checks. This occurs because of inadequate authorization enforcement on the API endpoint, allowing users to set domains on content nodes they are not permitted to access, either through user group privileges or start nodes. The vulnerable API endpoint allows this unauthorized assignment. The affected parameters or variables are not specified.
Recommendations
Update to Umbraco version 16.5.1 or later.
Update to Umbraco version 17.2.2.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Umbraco