CVE-2026-46609: Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog
Impact Authenticated users are able to inject HTML vulnerability into an input field, which is rendered in the confirmation dialog without proper output encoding.
Patches This issue has been patched in 17.4.0
Other sources
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Umbraco.Cmsto a version that resolves this vulnerability.Fixed in 17.4.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46609?
The severity of CVE-2026-46609 is rated as medium with a score of 4.6.
How do I fix CVE-2026-46609?
To fix CVE-2026-46609, upgrade to version 17.4.0 or later of Umbraco.Cms.
What type of vulnerability is CVE-2026-46609?
CVE-2026-46609 is classified as a Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-46609?
Authenticated users of the Umbraco.Cms software are affected by CVE-2026-46609.
When was CVE-2026-46609 published?
CVE-2026-46609 was published on May 21, 2026.