PT-2026-24487 · Umbraco+1 · Umbraco+1
Odgrso
·
Published
2026-03-10
·
Updated
2026-03-12
·
CVE-2026-31834
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Umbraco versions 15.3.1 through 16.5.0
Umbraco version 17.2.2
Description
Umbraco CMS contains a privilege escalation issue. Authenticated backoffice users with user management permissions may be able to gain elevated privileges due to inadequate authorization checks when modifying user group memberships. The system does not properly verify if a user is authorized to assign highly privileged roles.
Recommendations
Update to Umbraco version 16.5.1 or later.
Update to Umbraco version 17.2.2 or later.
Exploit
Fix
LPE
Improper Access Control
Improper Privilege Management
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Umbraco
Umbraco Cms