SCA: security update for Umbraco.Cms (GHSA-wr57-hqmp-fgvh)

high Tenable Cloud Security Plugin ID 448260

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member
and Public Access checks to the directly requested node but not to referenced nodes serialized through
Content Picker or Multi-Node Tree Picker properties, including pickers nested in Block List, Block Grid,
or Rich Text Editor blocks. When DeliveryApi:PublicAccess is enabled, an anonymous caller can retrieve a
protected node's name, route, and id through an unprotected referencing node and use ?expand to retrieve
full property values. When the Delivery API is instead gated by the organization-wide API key, a key
holder can still bypass per-node Public Access through the same expansion path. The same
RequestContextOutputExpansionStrategyV2 and ElementOnlyOutputExpansionStrategy path also bypasses allowed
or disallowed content-type alias restrictions for referenced content. Direct requests for the protected
node still return 401, and no integrity or availability impact is established. This issue is fixed in
versions 13.15.1, 17.5.3, and 18.0.2. (CVE-2026-69197)

Solution

Update the Umbraco.Cms library and its related packages to version 13.15.1 or later.

See Also

https://github.com/advisories/GHSA-wr57-hqmp-fgvh

Plugin Details

Severity: High

ID: 448260

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/23/2026

Updated: 9/23/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.57

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2026-69197

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/17/2026

Vulnerability Publication Date: 9/17/2026

Reference Information

CVE: CVE-2026-69197