CVE-2025-27601

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 285
CWE ID 863

Summary

CVE-2025-27601 is a vulnerability affecting Umbraco, a popular free and open-source .NET content management system. The issue lies in Umbraco's API management package, which allows low-privilege, authenticated users to modify data type information that should be restricted to users with access to the settings section. Prior versions 15.2.3 and 14.3.3 are impacted, and no known workarounds exist. This improper API access control issue can lead to unintended data changes, posing a potential security risk. The vulnerability is resolved in versions 15.2.3 and 14.3.3.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share