Skip to main content
Vulnerability Database/CVE-2024-48929

CVE-2024-48929: Umbraco CMS Auth Bypass Vulnerability

CVE-2024-48929 is an authentication bypass vulnerability in Umbraco CMS that fails to fully terminate server sessions during sign-out. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2024-48929 Overview

CVE-2024-48929 is an insufficient session expiration vulnerability in Umbraco CMS, a free and open source .NET content management system. During an explicit sign-out operation, the server-side session is not fully terminated. This leaves session artifacts valid after the user believes they have logged out. The flaw affects versions on the 13.x branch prior to 13.5.2 and versions on the 10.x branch prior to 10.8.7. Umbraco released patched builds in versions 13.5.2 and 10.8.7. The weakness is tracked under CWE-384: Session Fixation.

Critical Impact

An attacker who obtains a session token can continue to use it after the legitimate user signs out, enabling account takeover on shared or compromised endpoints.

Affected Products

  • Umbraco CMS 13.x branch prior to 13.5.2
  • Umbraco CMS 10.x branch prior to 10.8.7
  • Umbraco CMS deployments relying on the built-in sign-out workflow

Discovery Timeline

  • 2024-10-22 - CVE-2024-48929 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in the NVD database

Technical Details for CVE-2024-48929

Vulnerability Analysis

The vulnerability resides in the Umbraco sign-out flow. When a user explicitly signs out, the client-side session representation is removed, but the server does not fully invalidate the associated session state. An attacker who previously captured a valid session identifier can replay it against the Umbraco backoffice or member endpoints and resume authenticated activity.

Exploitation requires preconditions. The attacker must obtain a valid session token through means such as cross-site scripting, a shared workstation, network interception against a misconfigured deployment, or malware on the user's device. User interaction is required, since the condition is triggered by the victim performing a sign-out action that is expected to end the session.

The practical impact is limited confidentiality and integrity loss within the scope of the hijacked account. An attacker inheriting an editor or administrator session can read backoffice content and perform actions permitted to that role.

Root Cause

The root cause is incomplete server-side session termination logic during sign-out. The authentication subsystem removes the session cookie on the client but does not revoke the corresponding session state on the server, which contradicts the expected logout semantics defined under CWE-384.

Attack Vector

The attack vector is network-based with high attack complexity. An attacker needs an opportunity to capture a session token and must then reuse it after the victim signs out. No privileges are required by the attacker, but the victim must perform the sign-out action that creates the exploitable condition. Technical details are documented in the Umbraco GitHub Security Advisory GHSA-wxw9-6pv9-c3xc.

Detection Methods for CVE-2024-48929

Indicators of Compromise

  • Reuse of an Umbraco authentication cookie after the associated user issued a sign-out request.
  • Backoffice activity from a session identifier that overlaps or follows a logout event for the same user.
  • Requests originating from a new IP address or user agent reusing a previously issued session token.

Detection Strategies

  • Correlate signout or logout endpoint hits with subsequent authenticated requests carrying the same session identifier.
  • Baseline backoffice session lifetimes and flag sessions that remain active beyond the configured idle timeout after explicit logout.
  • Review web server and application logs for the Umbraco auth cookie being presented from multiple client fingerprints during the same session window.

Monitoring Recommendations

  • Forward Umbraco application logs and IIS or Kestrel access logs to a centralized logging platform for session correlation.
  • Alert on authenticated backoffice requests that occur after a successful sign-out event for the same account.
  • Monitor for unusual administrative actions following password changes or logout events, which may indicate replayed sessions.

How to Mitigate CVE-2024-48929

Immediate Actions Required

  • Upgrade Umbraco CMS to version 13.5.2 on the 13.x branch or 10.8.7 on the 10.x branch.
  • Force-expire all active backoffice and member sessions after the upgrade to invalidate any lingering tokens.
  • Rotate authentication secrets and cookie signing keys if session hijacking is suspected.
  • Review audit logs for suspicious backoffice activity that occurred after user logout events.

Patch Information

Umbraco addressed CVE-2024-48929 in versions 13.5.2 and 10.8.7. The patch corrects the sign-out workflow so the server-side session is fully terminated when a user signs out. Refer to the Umbraco Security Advisory GHSA-wxw9-6pv9-c3xc for upgrade guidance and release notes.

Workarounds

  • Shorten backoffice session timeout values to reduce the window in which a stale token remains valid.
  • Require re-authentication for sensitive backoffice actions until the patch is deployed.
  • Restrict backoffice access to trusted networks or VPN to limit opportunities for token capture.
  • Educate editors and administrators to close the browser after signing out on shared devices.
bash
# Example: upgrade Umbraco CMS via dotnet CLI to a patched version
dotnet add package Umbraco.Cms --version 13.5.2
# or, for the 10.x LTS branch
dotnet add package Umbraco.Cms --version 10.8.7

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.