CVE-2025-27601

MEDIUM

Umbraco Cms < 14.3.3 - Incorrect Authorization

Title source: rule
STIX 2.1

Description

Umbraco is a free and open source .NET content management system. An improper API access control issue has been identified Umbraco's API management package prior to versions 15.2.3 and 14.3.3, allowing low-privilege, authenticated users to create and update data type information that should be restricted to users with access to the settings section. The issue is patched in versions 15.2.3 and 14.3.3. No known workarounds are available.

Scores

CVSS v3 4.3
EPSS 0.0017
EPSS Percentile 37.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-863
Status published
Products (2)
nuget/Umbraco.Cms.Api.Management 15.0.0-rc1 - 15.2.3NuGet
umbraco/umbraco_cms < 14.3.3
Published Mar 11, 2025
Tracked Since Feb 18, 2026