Advisory Database
  • Advisories
  • Dependency Scanning
  1. nuget
  2. ›
  3. Umbraco.CMS
  4. ›
  5. CVE-2026-46616

CVE-2026-46616: Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers

May 21, 2026

Some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive ‘RedirectUrl’ from user-controlled query parameters vulnerable to malicious redirect attacks.

References

  • github.com/advisories/GHSA-2qjj-h6wp-c7h7
  • github.com/umbraco/Umbraco-CMS/pull/22561
  • github.com/umbraco/Umbraco-CMS/pull/22565
  • github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-2qjj-h6wp-c7h7
  • nvd.nist.gov/vuln/detail/CVE-2026-46616

Code Behaviors & Features

Detect and mitigate CVE-2026-46616 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 13.14.0, all versions starting from 17.3.0-rc before 17.4.0

Fixed versions

  • 13.14.0
  • 17.4.0

Solution

Upgrade to versions 13.14.0, 17.4.0 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Source file

nuget/Umbraco.CMS/CVE-2026-46616.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 22 May 2026 12:19:27 +0000.