CVE-2025-27601: Umbraco Allows Improper API Access Control to Low-Privilege Users to Data Type Functionality
(updated )
An improper API access control issue has been identified, allowing low-privilege, authenticated users to create and update data type information that should be restricted to users with access to the settings section.
References
- github.com/advisories/GHSA-6ffg-mjg7-585x
- github.com/umbraco/Umbraco-CMS
- github.com/umbraco/Umbraco-CMS/commit/d9fb6df16e9adf8656181cac8497fc5ba23321cd
- github.com/umbraco/Umbraco-CMS/commit/ebb6a580dc1da2c772a99838dc7b4660bf77eb9c
- github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-6ffg-mjg7-585x
- nvd.nist.gov/vuln/detail/CVE-2025-27601
Detect and mitigate CVE-2025-27601 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →