PT-2026-5347 · Umbraco · Umbraco Forms

Kevin Joensen

·

Published

2026-01-29

·

Updated

2026-03-02

·

CVE-2026-24687

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Umbraco Forms versions 16 through 17
Description Umbraco Forms, a form builder integrated with the Umbraco content management system, contains a flaw that allows an authenticated backoffice user to list and access files on the system's file system, and read their contents on Mac and Linux Umbraco installations. The issue affects versions 16 and 17. The /umbraco/forms/api/v1/export API endpoint is involved, and the fileName parameter is susceptible to path traversal attacks using sequences like ../ and ... Umbraco Cloud users are not affected as it runs in a Windows environment.
Recommendations Umbraco Forms version 16.4.1 Umbraco Forms version 17.1.1 If upgrading is not immediately possible, configure a WAF or reverse proxy to block requests containing path traversal sequences (../, ..) in the fileName parameter of the ''/umbraco/forms/api/v1/export'' endpoint. Restrict network access to the Umbraco backoffice to trusted IP ranges. Block the ''/umbraco/forms/api/v1/export'' endpoint entirely if the export feature is not required.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-24687
GHSA-HM5P-82G6-M3XH

Affected Products

Umbraco Forms