CVE-2025-27602: Umbraco Allows a Restricted Editor User to Delete Media Item or Access Unauthorized Content

Published Mar 11, 2025
·
Updated

Impact Via manipulation of backoffice API URLs it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to.

Patches Will be patched in 10.8.9 and 13.7.1

Workarounds None available.

Other sources

Umbraco is a free and open source .NET content management system. In versions of Umbraco's web backoffice program prior to versions 10.8.9 and 13.7.1, via manipulation of backoffice API URLs, it's possible for authenticated backoffice users to retrieve or delete content or media held within folders the editor does not have access to. The issue is patched in versions 10.8.9 and 13.7.1. No known workarounds are available.

MITRE

Affected Software

4 affected componentsFixes available
nuget/Umbraco.Cms.Web.Backoffice>=11.0.0-rc1<=13.7.0
13.7.1
nuget/Umbraco.Cms.Web.Backoffice<=10.8.8
10.8.9
Umbraco Umbraco CMS<10.8.9
Umbraco Umbraco CMS>=11.0.0<13.7.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade nuget/Umbraco.Cms.Web.Backoffice to a version that resolves this vulnerability.

    Fixed in 13.7.1
  2. Upgrade

    Upgrade nuget/Umbraco.Cms.Web.Backoffice to a version that resolves this vulnerability.

    Fixed in 10.8.9
  3. Upgrade

    Upgrade Umbraco backoffice program to a version that resolves this vulnerability.

    Fixed in 10.8.9
  4. Upgrade

    Upgrade Umbraco backoffice program to a version that resolves this vulnerability.

    Fixed in 13.7.1

Event History

Mar 11, 2025
Advisory Published
via GitHub·03:27 PM
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-27602?

CVE-2025-27602 has a high severity as it allows authenticated backoffice users to access or delete unauthorized content.

2

How do I fix CVE-2025-27602?

To fix CVE-2025-27602, update to Umbraco version 10.8.9 or 13.7.1.

3

What software is affected by CVE-2025-27602?

CVE-2025-27602 affects Umbraco versions from 11.0.0-rc1 up to 13.7.0 and 10.8.8 and below.

4

Are there any workarounds for CVE-2025-27602?

There are currently no available workarounds for CVE-2025-27602.

5

What type of vulnerability is CVE-2025-27602?

CVE-2025-27602 is a security vulnerability that involves unauthorized access to content in Umbraco's backoffice.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203