CVE-2026-46609
Last modified
CVE-2026-46609 is a medium-severity vulnerability rated 4.6/10 on the CVSS scale. Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper output encoding. This issue has been patched in version 17.4.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Umbraco | Umbraco Cms | >= 14.0.0, < 17.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-46609?
How severe is CVE-2026-46609?
How do I fix CVE-2026-46609?
Are you affected by CVE-2026-46609?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
