A high-severity vulnerability affecting Umbraco.Cms versions >= 12.0.0, < 13.15.1, >= 14.0.0-rc1, < 17.5.3, >= 18.0.0, < 18.0.2 CVE-2026-69197 with a CVSS score of 8.7, exists in the Umbraco Delivery API that allows an unauthorized caller to retrieve protected node information due to a lack of access checks during node expansion. This flaw type is a CWE-200 and CWE-862 issue, where an attacker can exploit it through an attack vector of network access with low complexity. The business impact is significant as confidential member-gated content referenced by publicly readable nodes can be disclosed to unauthenticated clients, potentially leading to the unauthorized disclosure of sensitive information such as pricing or internal documents. This vulnerability has a reduced severity when gated by an org-wide API key but remains exploitable in scenarios where the Delivery API is publicly accessible.
We recommend you to update Umbraco CMS to version 13.15.1, 17.5.3, or 18.0.2.[/subscribe_to_unlock_form]
A high-severity vulnerability affecting Umbraco.Cms versions >= 12.0.0, < 13.15.1, >= 14.0.0-rc1, < 17.5.3, >= 18.0.0, < 18.0.2 CVE-2026-69197 with a CVSS score of 8.7, exists in the Umbraco Delivery API that allows an unauthorized caller to retrieve protected node information due to a lack of access checks during node expansion. This flaw type is a CWE-200 and CWE-862 issue, where an attacker can exploit it through an attack vector of network access with low complexity. The business impact is significant as confidential member-gated content referenced by publicly readable nodes can be disclosed to unauthenticated clients, potentially leading to the unauthorized disclosure of sensitive information such as pricing or internal documents. This vulnerability has a reduced severity when gated by an org-wide API key but remains exploitable in scenarios where the Delivery API is publicly accessible.
We recommend you to update Umbraco CMS to version 13.15.1, 17.5.3, or 18.0.2.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]