CVE-2026-69197
Last modified
CVE-2026-69197 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenced nodes serialized through Content Picker or Multi-Node Tree Picker properties, including pickers nested in Block List, Block Grid, or Rich Text Editor blocks.
Description
Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenced nodes serialized through Content Picker or Multi-Node Tree Picker properties, including pickers nested in Block List, Block Grid, or Rich Text Editor blocks. When DeliveryApi:PublicAccess is enabled, an anonymous caller can retrieve a protected node's name, route, and id through an unprotected referencing node and use ?expand to retrieve full property values. When the Delivery API is instead gated by the organization-wide API key, a key holder can still bypass per-node Public Access through the same expansion path. The same RequestContextOutputExpansionStrategyV2 and ElementOnlyOutputExpansionStrategy path also bypasses allowed or disallowed content-type alias restrictions for referenced content. Direct requests for the protected node still return 401, and no integrity or availability impact is established. This issue is fixed in versions 13.15.1, 17.5.3, and 18.0.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| umbraco | Umbraco-CMS | >= 12.0.0, < 13.15.1; >= 14.0.0-rc1, < 17.5.3; >= 18.0.0, < 18.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-69197?
How severe is CVE-2026-69197?
How do I fix CVE-2026-69197?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69185Socket.IO enables bidirectional and low-latency communicatio…7.5
- CVE-2026-69186c-ares is an asynchronous resolver library. Prior to 1.34.7,…5.3
- CVE-2026-69189Hoppscotch is an open source API development ecosystem. Prio…7.6
- CVE-2026-6919Use after free in DevTools in Google Chrome prior to 147.0.7…9.6
- CVE-2026-69190Graylog is a free and open log management platform. From 6.3…6.3
- CVE-2026-69192ip-address is a library for parsing and manipulating IPv4 an…7.7
- CVE-2026-69198ip-address is a library for parsing and manipulating IPv4 an…6.9
- CVE-2026-6920Out of bounds read in GPU in Google Chrome on Android prior …9.6
- CVE-2026-69200node-opcua is an OPC UA implementation for TypeScript and No…3.7
- CVE-2026-69201Http4s is a Scala interface for HTTP services. Prior to 0.23…5.9
- CVE-2026-69202Http4s is a Scala interface for HTTP services. Prior to 0.23…7.5
- CVE-2026-69203Http4s is a Scala interface for HTTP services. Prior to 0.23…7.5
Are you affected by CVE-2026-69197?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
