PT-2026-24487 · Umbraco+1 · Umbraco+1

Odgrso

·

Published

2026-03-10

·

Updated

2026-03-12

·

CVE-2026-31834

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Umbraco versions 15.3.1 through 16.5.0 Umbraco version 17.2.2
Description Umbraco CMS contains a privilege escalation issue. Authenticated backoffice users with user management permissions may be able to gain elevated privileges due to inadequate authorization checks when modifying user group memberships. The system does not properly verify if a user is authorized to assign highly privileged roles.
Recommendations Update to Umbraco version 16.5.1 or later. Update to Umbraco version 17.2.2 or later.

Exploit

Fix

LPE

Improper Access Control

Improper Privilege Management

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-31834
GHSA-RHCG-3H8R-V6VP

Affected Products

Umbraco
Umbraco Cms