CVE-2026-27449Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed directly over the network without requiring a valid session or user credentials. By supplying a user-controlled identifier parameter (e.g., ?id=), an attacker can retrieve sensitive data associated with arbitrary records. Because no access control validation is performed, the endpoints are vulnerable to enumeration attacks, allowing attackers to iterate over identifiers and extract data at scale. An unauthenticated attacker can retrieve sensitive Engage-related data by directly querying the affected API endpoints. The vulnerability allows arbitrary record access through predictable or enumerable identifiers. The confidentiality impact is considered high. No direct integrity or availability impact has been identified. The scope of exposed data depends on the deployment but may include analytics data, tracking data, customer-related information, or other Engage-managed content. The vulnerability affects both v16 and v17. Patches have already been released. Users are advised to update to 16.2.1 or 17.1.1. No known workarounds are available.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-306CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-27); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-26: 1Mentions · 2026-02-27: 3Mentions · 2026-03-03: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 2Technical Details · 2026-03-03: 102-2602-2703-03
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-261
Patch1
2026-02-273
Disclosure3
2026-03-031
Disclosure1
Full discourse5 posts
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity: CVE-2026-27449 in Umbraco Engage.Forms exposes sensitive analytics & customer data via unauthenticated API access. Upgrade to 16.2.1/17.1.1 ASAP! 🔒 https://radar.offseq.com/threat/cve-2026-27449-cwe-284-improper-access-control-in--fadf6848 #OffSeq #Umbraco #Vu... https://t.co/SXBxSuXBEC

    Post summary

    CVE-2026-27449 in Umbraco Engage.Forms allows unauthenticated API access to sensitive data; users are urged to upgrade to 16.2.1/17.1.1.

    0001049
    270 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-27449 (CVSS:7.5, HIGH) is Awaiting Analysis. Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versi..https://nvd.nist.gov/vuln/detail/CVE-2026-27449 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A new CVE (CVE-2026-27449) with a CVSS score of 7.5 has been identified in Umbraco Engage, but no further details or mitigation steps are provided yet.

    0000037
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27449 Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoi… https://www.cve.org/CVERecord?id=CVE-2026-27449

    Post summary

    A vulnerability in Umbraco Engage affecting versions before 16.2.1 and 17.1.1 has been identified; the CVE record can be reviewed for details.

    00000165
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27449: Unauthenticated Data Exposure via Broken Access Control in Umbraco Engage A critical access control failure has been identified in Umbraco Engage (formerly uMarketingSuite), specifically affecting the Forms component. The vulnerability... https://cvereports.com/reports/CVE-2026-27449

    Post summary

    A new access control flaw in Umbraco Engage's Forms component allows unauthenticated data exposure; the announcement provides vulnerability details but no PoC, exploit, or patch information.

    0000034
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27449 Unauthenticated Data Exposure in Umbraco Engage API Endpoints Prior to 16.2.1 and 17.1.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27449

    Post summary

    The text announces CVE-2026-27449, noting unauthenticated data exposure in Umbraco Engage API endpoints before patch versions 16.2.1 and 17.1.1, without providing PoC, exploit code, or active exploitation details.

    0000032
    4.0K followersView on X

Explore more