Intel

AIKIDO-2026-339928

Umbraco.Cms is vulnerable to Incorrect Authorization

Incorrect AuthorizationGHSA-f7m5-5x7g-2p52 Published 2 days ago

88

High Risk

This Affects:

DOTNETUmbraco.Cms
15.2.0 - 17.6.1
Fixed in 17.6.2
18.0.0 - 18.1.0
Fixed in 18.1.1
Are you affected? Scan for Free

TL;DR

Umbraco.Cms Management API template create, update, and delete endpoints allow Content-only backoffice users to mutate Templates. Those operations should require Settings-section access. Under the default BackofficeDevelopment runtime mode, template content is compiled as Razor and executed on the server, which can lead to remote code execution. The fix requires Settings-section authorization on template mutations and related Settings-only Management API operations.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Umbraco.Cms is vulnerable to Incorrect Authorization in versions 15.2.0 - 17.6.1 and 18.0.0 - 18.1.0.

How to fix this

Upgrade the Umbraco.Cms library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform