Description
Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-h8wc-r4jh-mg7m
Patch x_refsource_misc
https://github.com/umbraco/Umbraco-CMS/commit/1f26f2c6f3428833892cde5c6d8441fb041e410e
Patch x_refsource_misc
https://github.com/umbraco/Umbraco-CMS/commit/20a4e475c8d7b91d263e4e103ef19f3644e7b569
Scores
CVSS v3
7.5
EPSS
0.0039
EPSS Percentile
60.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (3)
nuget/Umbraco.Cms.Infrastructure
9.0.0 - 10.6.1NuGet
nuget/Umbraco.Cms.Web.BackOffice
9.0.0 - 10.6.1NuGet
umbraco/umbraco_cms
10.0.0 - 10.6.1
Published
Jul 13, 2023
Tracked Since
Feb 18, 2026