CVE-2026-31834Disclosure(umbraco / umbraco_cms)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Umbraco is an ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions, authenticated backoffice users with permission to manage users, may be able to elevate their privileges due to insufficient authorization enforcement when modifying user group memberships. The affected functionality does not properly validate whether a user has sufficient privileges to assign highly privileged roles. This vulnerability is fixed in 16.5.1 and 17.2.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-284CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • umbraco_cms

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
umbraco_cms

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 103-1003-1103-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31834 Privilege Escalation in Umbraco CMS via Unauthorized User Group Membership Modification https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31834

    Post summary

    The text announces CVE-2026-31834, a Privilege Escalation vulnerability in Umbraco CMS caused by unauthorized user group modification. No proof of concept, exploit, or patch details are provided.

    0001032
    4.0K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Umbraco, Privilege Escalation, #CVE-2026-31834 (High) https://dailycve.com/umbraco-privilege-escalation-cve-2026-31834-high/

    Post summary

    The post announces a high‑severity privilege escalation flaw in Umbraco (CVE‑2026‑31834) but provides only basic technical details, with no PoC, exploit code, active exploitation, or patch information.

    0000029
    167 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31834 Umbraco is an http://ASP.NET CMS. From 15.3.1 to before 16.5.1 and 17.2.2, A privilege escalation vulnerability has been identified in Umbraco CMS. Under certain conditions,… https://www.cve.org/CVERecord?id=CVE-2026-31834

    Post summary

    A privilege‑escalation vulnerability affecting multiple Umbraco CMS versions has been publicly disclosed; no PoC, exploit, or patch information is currently available.

    0000081
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appumbracoumbraco_cms---

Explore more