CVE-2023-37267: Umbraco CMS

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Umbraco is a ASP.NET CMS. Under rare conditions a restart of Umbraco can allow unauthorized users access to admin-level permissions. This vulnerability was patched in versions 10.6.1, 11.4.2 and 12.0.1.

Affected products

  • Umbraco Umbraco CMS: from 10.0.0, before 10.6.1 (fixed in 10.6.1); from 11.0.0, before 11.4.2 (fixed in 11.4.2); from 12.0.0, before 12.0.1 (fixed in 12.0.1)

Published 2023-07-13. Last modified 2026-06-17.