Event

It's Partner Summit season!

Find an event near you →

Security Advisory, October 6, 2026: Security Patches for Umbraco CMS now available

We recommend you upgrade to the latest patch

Anders Nis Herforth Larsen
Written by Anders Nis Herforth Larsen

Four vulnerabilities have been discovered and resolved in Umbraco CMS: two classified as moderate and two as low. Today, we have released patches for the affected versions and recommend upgrading. 

What’s affected?

Umbraco CMS

Moderate Severity

Affected Product Version Range:

  • 17.0.0 - 17.7.0

  • 18.0.0 - 18.2.0

See full advisory on GitHub

Moderate Severity

Affected Product Version Range:

  • 17.0.0 - 17.7.0

  • 18.0.0 - 18.2.0

See full advisory on GitHub

Low Severity

Affected Product Version Range:

  • 17.0.0 - 17.7.0

  • 18.0.0 - 18.2.0

See full advisory on GitHub

Low Severity

Affected Product Version Range:

  • 17.0.0 - 17.7.0

  • 18.0.0 - 18.2.0

See full advisory on GitHub

How to fix the vulnerability

If you're using Umbraco CMS 17 or 18, you are able to upgrade to a new patch version of these releases the way you would normally upgrade.

The Umbraco CMS patched versions are: 17.7.1 and 18.2.1.

Please note: If your site, or a package you use, provides a custom media path scheme, upgrading alone does not fully resolve the media vulnerability (GHSA-7pj9-jmp9-p86q), see the documentation for more detail. Custom media path schemes are not a typical extension point used for Umbraco websites.

How do you check which version you are on? 

Reach out to your technical contact for your Umbraco site with this blog post, and they will be able to take care of the necessary precautions.

If your project is on Umbraco Cloud

If your Umbraco project is hosted on Umbraco Cloud, an automatic upgrade will be rolled out today to fix the vulnerabilities for Umbraco CMS - no action needed. If your project uses a custom media path scheme, see the note above, as an additional step is needed after the upgrade.

If you cannot upgrade immediately

Upgrading is the only complete fix. There is no configuration-level workaround that fully resolves these issues. Until you can upgrade, you can reduce your exposure by limiting backoffice access especially to the Content and Media sections to trusted users, making sure backoffice and API accounts only have the permissions they need, and, where possible, restricting access to the back office to trusted networks. If your site relies on file upload restrictions, configure an explicit allow list of the file extensions your site needs rather than relying on the default deny list.

What if I’m on an unsupported version?

Unsupported versions can be subject to the vulnerability, but will not receive a patch. If you are running a version that is past End-of-Life, the recommended path is to upgrade to a supported major version e.g. Umbraco 17 (LTS) or Umbraco 18.

You can check the support status of your version on our
Long-term Support and End-of-Life page. Feel free to book a discovery call with us to talk about your options.

What we know about the vulnerability

Umbraco CMS: Content access restrictions not enforced for content versions

Access checks for some of the backoffice's content version features were incomplete. As a result, an authenticated back-office user could view content they had not been granted access to, such as content outside the parts of the content tree assigned to them, - including unpublished content and earlier versions.

Exploitation requires a valid backoffice account with access to the Content section, and the issue cannot be exploited anonymously. Sites that restrict which content individual backoffice users can see are affected. Sites where every backoffice user with access to the Content section is trusted with all content are not meaningfully affected.

The severity of this vulnerability is: Moderate. It requires an authenticated backoffice account, and the impact is limited to viewing restricted content and changing one related setting.

Umbraco CMS: Restricted users could delete media outside their permitted area

An access control weakness affected media management in the backoffice. Under certain conditions, a backoffice user with restricted media permissions could cause media files outside the part of the media library they are authorised to access to be deleted. Deleted files may not be recoverable without a backup.

Exploitation requires an authenticated backoffice account with access to the Media section, and the issue cannot be exploited anonymously. Sites that restrict which parts of the media library individual backoffice or API users can access are affected.

The severity of this vulnerability is: Moderate. It requires an authenticated backoffice account with access to the Media section, and the impact is limited to the deletion of media files, no data is exposed.

Umbraco CMS: File upload type restrictions could be bypassed

A weakness in how file names were validated during backoffice file uploads meant that the configured file type restrictions could be bypassed in certain circumstances. As a result, a file of a type the site is configured to reject could be accepted by the upload process.

Exploitation requires a valid backoffice account, and the issue cannot be exploited anonymously. Sites that rely on the upload file type configuration to keep particular file types out of the installation are affected, including sites using the default configuration.

The severity of this vulnerability is: Low. Uploaded files are initially held in a temporary location that is not served over HTTP or executed by the application, and are removed automatically, so the issue does not on its own provide a directly exploitable path.

Umbraco CMS: Unauthenticated access to backoffice real-time endpoints

Certain real-time communication endpoints used by the Umbraco backoffice could be accessed without authentication. A client connecting to these endpoints could receive limited information about editorial activity in the backoffice, such as when content, including unpublished content, was being created or edited.

Every publicly reachable Umbraco site running an affected version is impacted. No authentication or prior access is required.

The severity of this vulnerability is: Low. The exposure is limited to activity information: no content, credentials, or management capabilities are exposed, and the issue does not allow content to be changed.

Credit

We’d like to thank sakilahamed for reporting the Umbraco CMS content version vulnerability, am7maaz for reporting the Umbraco CMS media vulnerability, and lichoin for the PreviewHub vulnerability.

Any questions?

If you have any questions or comments about this advisory, make sure to get in touch with us directly via the Security Advisories. Alternatively, you can reach out to the dedicated security email address listed at https://umbraco.com/security. Here you can also find information on how we handle security-related issues.

For direct communication related to security in Umbraco products, please sign up for the dedicated security mailing list.