Impact
The vulnerability allows a caller to obtain details of protected content – such as node name, route and identifier – through the Content Delivery API. Referenced nodes serialized via Content Picker, Multi‑Node Tree Picker or embedded blocks are not subject to the same member or Public Access checks as the direct node. As a result, an anonymous user or anyone holding an organization‑wide API key can leverage the ?expand query to expose protected nodes, increasing confidentiality risk while leaving integrity and availability unaffected.
Affected Systems
Versions of Umbraco CMS older than 13.15.1, 17.5.3, and 18.0.2 are vulnerable. Any deployment of Umbraco CMS that still hosts these releases, including earlier major releases, falls within the impact scope.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high severity vulnerability. The EPSS score of <1% suggests that exploitation opportunities are currently low, and the vulnerability is not listed in the CISA KEV catalog. An attacker could target the Delivery API endpoint with minimal effort, either anonymously or using a key, to trigger the defensive bypass and retrieve sensitive metadata. The lack of integrity or availability impact limits the consequences to confidentiality exposure only.
OpenCVE Enrichment
Github GHSA