Description
Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenced nodes serialized through Content Picker or Multi-Node Tree Picker properties, including pickers nested in Block List, Block Grid, or Rich Text Editor blocks. When DeliveryApi:PublicAccess is enabled, an anonymous caller can retrieve a protected node's name, route, and id through an unprotected referencing node and use ?expand to retrieve full property values. When the Delivery API is instead gated by the organization-wide API key, a key holder can still bypass per-node Public Access through the same expansion path. The same RequestContextOutputExpansionStrategyV2 and ElementOnlyOutputExpansionStrategy path also bypasses allowed or disallowed content-type alias restrictions for referenced content. Direct requests for the protected node still return 401, and no integrity or availability impact is established. This issue is fixed in versions 13.15.1, 17.5.3, and 18.0.2.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a caller to obtain details of protected content – such as node name, route and identifier – through the Content Delivery API. Referenced nodes serialized via Content Picker, Multi‑Node Tree Picker or embedded blocks are not subject to the same member or Public Access checks as the direct node. As a result, an anonymous user or anyone holding an organization‑wide API key can leverage the ?expand query to expose protected nodes, increasing confidentiality risk while leaving integrity and availability unaffected.

Affected Systems

Versions of Umbraco CMS older than 13.15.1, 17.5.3, and 18.0.2 are vulnerable. Any deployment of Umbraco CMS that still hosts these releases, including earlier major releases, falls within the impact scope.

Risk and Exploitability

The CVSS base score of 8.7 indicates a high severity vulnerability. The EPSS score of <1% suggests that exploitation opportunities are currently low, and the vulnerability is not listed in the CISA KEV catalog. An attacker could target the Delivery API endpoint with minimal effort, either anonymously or using a key, to trigger the defensive bypass and retrieve sensitive metadata. The lack of integrity or availability impact limits the consequences to confidentiality exposure only.

Generated by OpenCVE AI on September 20, 2026 at 04:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest releases 13.15.1, 17.5.3, or 18.0.2, or any later patches that address the public access bypass.
  • If upgrading immediately is not possible, disable public access in the Delivery API or recharge all Delivery API calls behind an organization‑wide API key to prevent anonymous leakage.
  • Audit existing API keys and revoke or rotate any that were shared or exposed, since they can still bypass per‑node Public Access when the API is attended.

Generated by OpenCVE AI on September 20, 2026 at 04:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wr57-hqmp-fgvh Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
History

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Umbraco
Umbraco umbraco Cms
Vendors & Products Umbraco
Umbraco umbraco Cms

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenced nodes serialized through Content Picker or Multi-Node Tree Picker properties, including pickers nested in Block List, Block Grid, or Rich Text Editor blocks. When DeliveryApi:PublicAccess is enabled, an anonymous caller can retrieve a protected node's name, route, and id through an unprotected referencing node and use ?expand to retrieve full property values. When the Delivery API is instead gated by the organization-wide API key, a key holder can still bypass per-node Public Access through the same expansion path. The same RequestContextOutputExpansionStrategyV2 and ElementOnlyOutputExpansionStrategy path also bypasses allowed or disallowed content-type alias restrictions for referenced content. Direct requests for the protected node still return 401, and no integrity or availability impact is established. This issue is fixed in versions 13.15.1, 17.5.3, and 18.0.2.
Title Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
Weaknesses CWE-200
CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Umbraco Umbraco Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T17:23:18.418Z

Reserved: 2026-08-03T16:00:23.483Z

Link: CVE-2026-69197

cve-icon Vulnrichment

Updated: 2026-09-17T17:23:05.991Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T16:17:41.010

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-69197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-862

    Missing Authorization