CVE-2023-37267

HIGH

Umbraco Cms < 10.6.1 - Improper Access Control

Title source: rule
STIX 2.1

Description

Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 60.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (3)
nuget/Umbraco.Cms.Infrastructure 9.0.0 - 10.6.1NuGet
nuget/Umbraco.Cms.Web.BackOffice 9.0.0 - 10.6.1NuGet
umbraco/umbraco_cms 10.0.0 - 10.6.1
Published Jul 13, 2023
Tracked Since Feb 18, 2026