CVE-2026-46616: Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers
(updated )
Some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive ‘RedirectUrl’ from user-controlled query parameters vulnerable to malicious redirect attacks.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-46616 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →