{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/umbraco/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:umbraco:cms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-69197"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Umbraco CMS (12.0.0-13.15.0, 14.0.0-17.5.2, 18.0.0-18.0.1)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","api-security","umbraco","cve-2026-69197"],"_cs_type":"advisory","_cs_vendors":["Umbraco"],"content_html":"\u003cp\u003eUmbraco CMS contains a critical authorization bypass vulnerability, tracked as CVE-2026-69197, affecting the Content Delivery API. The vulnerability stems from a flaw in the controller-layer access validation, which only enforces member-gated (Public Access) protections when a protected node is requested directly. When a publicly accessible (unprotected) node references a protected node via a Content Picker, Multi-Node Tree Picker, or nested block structures, the Delivery API fails to propagate access checks during expansion.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can supply the '?expand' query parameter in a request for a public node to force the API to serialize and disclose the full property values of linked protected content. While a direct request to the protected node correctly returns a 401 Unauthorized status, the expansion mechanism exposes the internal properties, routes, and identifiers of member-gated data. This affects Umbraco CMS versions 12.0.0 through 13.15.0, 14.0.0 through 17.5.2, and 18.0.0 through 18.0.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized retrieval of sensitive, member-gated information such as pricing structures, internal documentation, and restricted articles. The impact is highest when the Delivery API is configured for public access, though it remains exploitable in environments gated by API keys if the attacker possesses legitimate access to a public node that references protected content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Umbraco CMS to version 13.15.1, 17.5.3, or 18.0.2 to address CVE-2026-69197.\u003c/li\u003e\n\u003cli\u003eAudit Delivery API logs for high-frequency use of the '?expand' query parameter across public nodes to identify potential enumeration or data exfiltration attempts.\u003c/li\u003e\n\u003cli\u003eReview Content Picker configurations to identify nodes that reference sensitive, member-gated content, and restrict API access to these paths until patching is complete.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T19:14:22Z","date_published":"2026-09-17T19:14:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-umbraco-api-leak/","summary":"Umbraco CMS contains an authorization bypass vulnerability (CVE-2026-69197) in the Delivery API where protected content is leaked when referenced by an unprotected node through expansion parameters.","title":"Umbraco Delivery API Authorization Bypass via Node Expansion","url":"https://feed.craftedsignal.io/briefs/2026-09-umbraco-api-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Umbraco","version":"https://jsonfeed.org/version/1.1"}