CVE-2025-27602: Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content
Impact Via manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to.
Patches Will be patched in 10.8.9 and 13.7.1
Workarounds None available.
Other sources
Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffice API URLs, it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. The issue is patched in versions 10.8.9 and 13.7.1. No known workarounds are available.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Umbraco.Cms.Web.Backofficeto a version that resolves this vulnerability.Fixed in 13.7.1 - Upgrade
Upgrade
nuget/Umbraco.Cms.Web.Backofficeto a version that resolves this vulnerability.Fixed in 10.8.9 - Upgrade
Upgrade
Umbraco backoffice programto a version that resolves this vulnerability.Fixed in 10.8.9 - Upgrade
Upgrade
Umbraco backoffice programto a version that resolves this vulnerability.Fixed in 13.7.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27602?
CVE-2025-27602 has a high severity as it allows authenticated backoffice users to access or delete unauthorized content.
How do I fix CVE-2025-27602?
To fix CVE-2025-27602, update to Umbraco version 10.8.9 or 13.7.1.
What software is affected by CVE-2025-27602?
CVE-2025-27602 affects Umbraco versions from 11.0.0-rc1 up to 13.7.0 and 10.8.8 and below.
Are there any workarounds for CVE-2025-27602?
There are currently no available workarounds for CVE-2025-27602.
What type of vulnerability is CVE-2025-27602?
CVE-2025-27602 is a security vulnerability that involves unauthorized access to content in Umbraco's backoffice.