Intel

AIKIDO-2026-115380

Umbraco.Cms is vulnerable to Missing Authorization

Missing AuthorizationGHSA-w5q3-9wf8-43gg Published 2 days ago

65

Medium Risk

This Affects:

DOTNETUmbraco.Cms
14.0.0 - 17.6.1
Fixed in 17.6.2
18.0.0 - 18.1.0
Fixed in 18.1.1
Are you affected? Scan for Free

TL;DR

Umbraco.Cms Management API indexer and searcher endpoints require only an authenticated backoffice user and skip the Settings-section authorization check used by comparable administrative endpoints. Results are not limited to the caller's content, media, or member permissions. A lowest-privilege backoffice user, including one restricted to a single content branch, can read unpublished content, Public Access-protected content, and member records including sensitive data. The fix requires Settings-section access on those routes and additionally requires Members-section access to query member indexes.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Umbraco.Cms is vulnerable to Missing Authorization in versions 14.0.0 - 17.6.1 and 18.0.0 - 18.1.0.

How to fix this

Upgrade the Umbraco.Cms library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform