Intel

AIKIDO-2025-10158

Umbraco.Cms.Web.Backoffice is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized ActorCVE-2025-27602 Published Mar 17, 2025

49

Medium Risk

This Affects:

DOTNETUmbraco.Cms.Web.Backoffice
9.0.0 - 10.8.8
Fixed in 10.8.9
11.0.0 - 13.7.0
Fixed in 13.7.1
14.0.0 - 14.3.2
Fixed in 14.3.3
15.0.0 - 15.2.2
Fixed in 15.2.3
Are you affected? Scan for Free

TL;DR

Authenticated backoffice users can exploit manipulated API URLs to bypass access restrictions, allowing them to retrieve or delete content and media stored in folders they are not authorized to access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Umbraco.Cms.Web.Backoffice is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 9.0.0 - 10.8.8, 11.0.0 - 13.7.0, 14.0.0 - 14.3.2 and 15.0.0 - 15.2.2.

How to fix this

Upgrade the Umbraco.Cms.Web.Backoffice library to the patch version.