Skip to main content
Vulnerability Database/CVE-2025-27601

CVE-2025-27601: Umbraco CMS Auth Bypass Vulnerability

CVE-2025-27601 is an authentication bypass flaw in Umbraco CMS allowing low-privilege users to access restricted API management functions. This article covers technical details, affected versions, and mitigation steps.

Published:

CVE-2025-27601 Overview

CVE-2025-27601 is an improper authorization vulnerability [CWE-285] in the Umbraco CMS API management package. The flaw allows low-privilege authenticated users to create and update data type information that should be restricted to users with access to the settings section. The issue affects Umbraco versions prior to 15.2.3 and 14.3.3, and is fixed in those releases.

Critical Impact

Authenticated back-office users without settings privileges can invoke Data Type management endpoints, enabling unauthorized modification of content type definitions used across the site.

Affected Products

  • Umbraco CMS versions prior to 15.2.3 in the 15.x branch
  • Umbraco CMS versions prior to 14.3.3 in the 14.x branch
  • Umbraco.Cms.Api.Management package (Data Type controllers)

Discovery Timeline

  • 2025-03-11 - CVE-2025-27601 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-27601

Vulnerability Analysis

Umbraco's back-office API exposes controllers for creating and copying data types under Umbraco.Cms.Api.Management.Controllers.DataType. These endpoints should be reachable only by users granted access to the Settings section. In vulnerable releases, the controllers lacked the appropriate authorization policy attributes.

Any authenticated back-office user, including accounts limited to Content or other low-privilege sections, could call these endpoints. The result is an integrity issue: attackers can create new data types or copy existing ones, altering the schema that editors and templates rely on.

Root Cause

The root cause is a missing [Authorize] policy on the CreateDataTypeController and CopyDataTypeController action classes. Without the settings-scoped policy, the default authenticated-user check applied, permitting broader access than intended. The patches add using Microsoft.AspNetCore.Authorization; and attach the correct authorization requirement to gate the endpoints.

Attack Vector

Exploitation requires a valid back-office session but no elevated privileges. An attacker with a low-privilege account authenticates to the Umbraco management API and issues POST requests to the create or copy Data Type endpoints. No user interaction from an administrator is required.

text
// Patch: src/Umbraco.Cms.Api.Management/Controllers/DataType/CreateDataTypeController.cs
-	tusing Asp.Versioning;
+using Asp.Versioning;
+using Microsoft.AspNetCore.Authorization;
 using Microsoft.AspNetCore.Http;
 using Microsoft.AspNetCore.Mvc;
 using Umbraco.Cms.Api.Management.Factories;

// Patch: src/Umbraco.Cms.Api.Management/Controllers/DataType/CopyDataTypeController.cs
 using Asp.Versioning;
+using Microsoft.AspNetCore.Authorization;
 using Microsoft.AspNetCore.Http;
 using Microsoft.AspNetCore.Mvc;
 using Umbraco.Cms.Api.Management.ViewModels.DataType;

Source: Umbraco-CMS commit d9fb6df and commit ebb6a58.

Detection Methods for CVE-2025-27601

Indicators of Compromise

  • Unexpected new or copied data type entries in the Umbraco settings section that do not match change management records.
  • Successful HTTP 200 responses on /umbraco/management/api/*/data-type create or copy endpoints from users without Settings section access.
  • Audit log entries showing data type modifications performed by content-editor or other non-administrator accounts.

Detection Strategies

  • Enable and forward Umbraco back-office audit logs to a central SIEM and alert on data type create or copy events attributed to non-settings users.
  • Instrument the reverse proxy or application gateway to log requests to Data Type management API routes with the authenticated user identity and role claims.
  • Baseline the set of accounts historically making schema changes and alert on deviations.

Monitoring Recommendations

  • Monitor the Umbraco umbracoLog table or configured log sink for Save and Copy events on IDataType entities.
  • Track authentication events and correlate low-privilege session tokens with calls to privileged API endpoints.
  • Review scheduled configuration exports for unexplained changes to data type definitions between deployments.

How to Mitigate CVE-2025-27601

Immediate Actions Required

  • Upgrade Umbraco CMS to version 15.2.3 on the 15.x branch or 14.3.3 on the 14.x branch as soon as possible.
  • Audit existing back-office accounts and remove unnecessary access, applying least privilege for content editors and other non-settings roles.
  • Review data type definitions for unauthorized additions or modifications and restore known-good state from source control if tampering is found.

Patch Information

The fix is delivered in Umbraco CMS 15.2.3 and 14.3.3. Both releases add Microsoft.AspNetCore.Authorization policies to CreateDataTypeController and CopyDataTypeController so that only users with access to the Settings section can invoke them. See the GitHub Security Advisory GHSA-6ffg-mjg7-585x for full details.

Workarounds

  • No official workarounds are available; upgrading to a patched version is required.
  • As a compensating control, restrict network access to the /umbraco management endpoints to trusted administrator networks or VPN users until patches are applied.
bash
# Example: verify installed Umbraco.Cms package version in a .NET project
dotnet list package | grep -i "Umbraco.Cms"

# Update to a patched version (choose the branch that matches your deployment)
dotnet add package Umbraco.Cms --version 15.2.3
# or for the 14.x branch
dotnet add package Umbraco.Cms --version 14.3.3

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.