Intel

AIKIDO-2025-10288

Umbraco.Cms is vulnerable to Observable Response Discrepancy

Observable Response DiscrepancyCVE-2025-46736

51

Medium Risk

This Affects:

dotnetUmbraco.Cms
9.0.0 - 10.8.9
Fixed in 10.8.10
11.0.0 - 13.8.0
Fixed in 13.8.1

TL;DR

Affected versions of the package are vulnerable to observable response discrepancy. By analyzing the timing of post-login API responses, an attacker can infer the existence of user accounts.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Umbraco.Cms is vulnerable to Observable Response Discrepancy in versions 11.0.0 - 13.8.0 and 9.0.0 - 10.8.9.

How to fix this

Upgrade the Umbraco.Cms library to the patch version.