PT-2026-42686 · Umbraco+2 · Umbraco+1

CVE-2026-46616

·

Published

2026-05-21

·

Updated

2026-06-10

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Umbraco versions prior to 13.14.0 Umbraco versions prior to 17.4.0
Description Certain Surface Controllers supporting member-related operations fail to validate redirect URLs. This allows Razor templates that derive the RedirectUrl from user-controlled query parameters to be susceptible to malicious redirect attacks. The issue specifically affects the UmbLoginStatusController, UmbProfileController, and UmbRegisterController controllers.
Recommendations Update to version 13.14.0. Update to version 17.4.0. As a temporary workaround, ensure every Razor form posting to UmbLoginStatusController, UmbProfileController, or UmbRegisterController passes a concrete, trusted RedirectUrl into the route values of Html.BeginUmbracoForm.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46616
GHSA-2QJJ-H6WP-C7H7

Affected Products

Umbraco
Umbraco Cms