CVE-2024-28868: Umbraco possible user enumeration vulnerability

Published Mar 20, 2024
·
Updated

Impact A user enumeration attack is possible.

Affected versions Umbraco 10 with access to the native login screen

Patches This is fixed in 10.8.5

Workarounds Disabling the native login screen, by exclusively use external logins.

Other sources

Umbraco is an ASP.NET content management system. Umbraco 10 prior to 10.8.4 with access to the native login screen is vulnerable to a possible user enumeration attack. This issue was fixed in version 10.8.5. As a workaround, one may disable the native login screen by exclusively using external logins.

NVD

Affected Software

2 affected componentsFixes available
nuget/UmbracoCMS>=10.0.0<10.8.5
10.8.5
Umbraco Umbraco CMS>=10.0.0<10.8.5

Event History

Mar 20, 2024
Advisory Published
via GitHub·05:54 PM
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-28868?

CVE-2024-28868 is a user enumeration vulnerability that could allow attackers to identify valid usernames.

2

How do I fix CVE-2024-28868?

The vulnerability can be fixed by upgrading Umbraco CMS to version 10.8.5 or later.

3

What versions are affected by CVE-2024-28868?

CVE-2024-28868 affects Umbraco CMS version 10.0.0 to 10.8.4.

4

Is there a workaround for CVE-2024-28868?

A temporary workaround for CVE-2024-28868 is to disable the native login screen and use exclusively external logins.

5

Who is impacted by CVE-2024-28868?

Users with access to the native login screen of the affected Umbraco versions are impacted by CVE-2024-28868.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203