Missing Authorization Affecting umbraco.cms.web.common package, versions [12.0.0,13.15.1)[14.0.0-rc1,17.5.3)[18.0.0-beta1,18.0.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.66% (50th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-UMBRACOCMSWEBCOMMON-20074844
  • published24 Sept 2026
  • disclosed17 Sept 2026
  • creditsuryadina

Introduced: 17 Sep 2026

NewCVE-2026-69197  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade Umbraco.Cms.Web.Common to version 13.15.1, 17.5.3, 18.0.2 or higher.

Overview

Umbraco.Cms.Web.Common is a package containing the web assembly needed to run Umbraco CMS.

Affected versions of this package are vulnerable to Missing Authorization in the Content Delivery API, which enforces Public Access protection only on directly requested nodes, expanding Content Picker and Multi-Node Tree Picker references without validating access to the referenced node and without applying the content type alias restrictions. An attacker can read protected content, obtaining names, routes, and IDs in all cases and full property values when using ?expand, by requesting a public node that references the protected one, including through pickers nested inside Block List, Block Grid, or Rich Text Editor properties. This requires a public node to reference protected content and the Delivery API to be reachable, typically with DeliveryApi:PublicAccess: true, and a direct request for the protected node still returns 401, which masks the exposure from anyone testing the node directly.

CVSS Base Scores

version 4.0
version 3.1