CVE-2026-27449: Umbraco.Engage.Forms Allows Unauthorized Access to Multiple API Endpoints

Published Feb 26, 2026
·
Updated

Description A vulnerability has been identified in Umbraco Engage where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed directly over the network without requiring a valid session or user credentials. By supplying a user-controlled identifier parameter (e.g., ?id=), an attacker can retrieve sensitive data associated with arbitrary records.

Because no access control validation is performed, the endpoints are vulnerable to enumeration attacks, allowing attackers to iterate over identifiers and extract data at scale.

Impact An unauthenticated attacker can retrieve sensitive Engage-related data by directly querying the affected API endpoints. The vulnerability allows arbitrary record access through predictable or enumerable identifiers.

The confidentiality impact is considered high. No direct integrity or availability impact has been identified.

The scope of exposed data depends on the deployment but may include analytics data, tracking data, customer-related information, or other Engage-managed content.

Patches The vulnerability affects both v16 and v17. Patches have already been released. Users are advised to update to 16.2.1 or 17.1.1

Other sources

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed directly over the network without requiring a valid session or user credentials. By supplying a user-controlled identifier parameter (e.g., ?id=), an attacker can retrieve sensitive data associated with arbitrary records. Because no access control validation is performed, the endpoints are vulnerable to enumeration attacks, allowing attackers to iterate over identifiers and extract data at scale. An unauthenticated attacker can retrieve sensitive Engage-related data by directly querying the affected API endpoints. The vulnerability allows arbitrary record access through predictable or enumerable identifiers. The confidentiality impact is considered high. No direct integrity or availability impact has been identified. The scope of exposed data depends on the deployment but may include analytics data, tracking data, customer-related information, or other Engage-managed content. The vulnerability affects both v16 and v17. Patches have already been released. Users are advised to update to 16.2.1 or 17.1.1. No known workarounds are available.

MITRE

Affected Software

3 affected componentsFixes available
Umbraco Umbraco Engage<16.2.1, <17.1.1
nuget/Umbraco.Engage.Forms>=17.0.0<17.1.1
17.1.1
nuget/Umbraco.Engage.Forms<16.2.1
16.2.1

Event History

Feb 26, 2026
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:20 PM
DescriptionSeverityWeakness
Feb 27, 2026
Advisory Published
via GitHub·06:35 PM
Data Sourced
via GitHub·06:35 PM
DescriptionSeverityWeaknessAffected Software
Jun 28, 58142
Event
via FIRST·02:44 AM

Frequently Asked Questions

1

What is the severity of CVE-2026-27449?

CVE-2026-27449 has been classified as a moderate severity vulnerability due to unauthorized access to multiple API endpoints.

2

How do I fix CVE-2026-27449?

To fix CVE-2026-27449, update Umbraco Engage.Forms to version 17.1.1 or 16.2.1.

3

What are the affected versions of Umbraco Engage for CVE-2026-27449?

CVE-2026-27449 affects Umbraco Engage versions before 17.1.1 and between 16.0.0 and 16.2.1.

4

What types of attacks can CVE-2026-27449 lead to?

CVE-2026-27449 can lead to unauthorized access to sensitive data through the exposed API endpoints.

5

Is authentication required for the API endpoints in CVE-2026-27449?

No, the affected API endpoints in CVE-2026-27449 do not enforce authentication or authorization checks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203