Umbraco.Cms is vulnerable to Missing Authorization
65
Medium Risk
Umbraco.Cms Management API indexer and searcher endpoints require only an authenticated backoffice user and skip the Settings-section authorization check used by comparable administrative endpoints. Results are not limited to the caller's content, media, or member permissions. A lowest-privilege backoffice user, including one restricted to a single content branch, can read unpublished content, Public Access-protected content, and member records including sensitive data. The fix requires Settings-section access on those routes and additionally requires Members-section access to query member indexes.
You are affected if you are using a version that falls within the vulnerable range.
Umbraco.Cms is vulnerable to Missing Authorization in versions 14.0.0 - 17.6.1 and 18.0.0 - 18.1.0.
Upgrade the Umbraco.Cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.