CVE-2025-27601
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-27601 is a vulnerability affecting Umbraco, a popular free and open-source .NET content management system. The issue lies in Umbraco's API management package, which allows low-privilege, authenticated users to modify data type information that should be restricted to users with access to the settings section. Prior versions 15.2.3 and 14.3.3 are impacted, and no known workarounds exist. This improper API access control issue can lead to unintended data changes, posing a potential security risk. The vulnerability is resolved in versions 15.2.3 and 14.3.3.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- CMs
Affected Vendors
- Pluck -