Junglewise Threat Intelligence

CVE-2025-67288: Umbraco CMS arbitrary file upload in PDF processing

CVE-2025-67288 · Severity: critical · CVSS 10 · Published 2025-12-22

Executive brief

Umbraco CMS, a popular platform for managing website content, contains a vulnerability that could allow an attacker to take full control of the web server. By uploading a specially crafted PDF file, an unauthorized user may be able to execute malicious code, potentially leading to data theft or service disruption. The software provider disputes this report, stating that administrators are responsible for configuring proper file upload restrictions within the system.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in Umbraco CMS v16.3.3. The flaw allows a remote, unauthenticated attacker to upload a malicious file disguised as a PDF, which can then be executed on the server to achieve remote code execution (RCE). The vulnerability is currently disputed by the vendor, who argues that file validation is a configuration responsibility of the system administrator rather than a defect in the CMS core. This issue is noted as being functionally similar to CVE-2023-49279.

Affected products

  • Umbraco Umbraco CMS 16.3.3

Timeline

  • 2025-12-22: disclosed
  • 2025-12-22: advisory
  • 2026-01-02: other: Vulnerability disputed by vendor

References