Junglewise Threat Intelligence

CVE-2026-46616: Umbraco CMS open redirect in member Surface Controllers

CVE-2026-46616 · Severity: medium · CVSS 5.4 · Published 2026-06-10

Executive brief

Umbraco, a popular content management system, contains a security flaw that could allow attackers to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker can make a legitimate Umbraco site send the user to a phishing or malware site, potentially damaging the organization's reputation and leading to credential theft. This issue affects specific member-related features like login status, registration, and profile management.

Technical details

An open redirect vulnerability exists in Umbraco CMS due to insufficient validation of the 'RedirectUrl' parameter within specific Surface Controllers, namely UmbLoginStatusController, UmbRegisterController, and UmbProfileController. The root cause is the failure to verify if a redirect destination is local before execution. An unauthenticated remote attacker can exploit this by crafting a URL that includes a malicious external destination in the query parameters. If a user interacts with this link, the application will redirect them to the attacker-controlled site. The vulnerability has been addressed in versions 13.14.0 and 17.4.0 by implementing 'Url.IsLocalUrl()' validation.

Affected products

  • Umbraco Umbraco CMS < 13.14.0, < 17.4.0

Timeline

  • 2026-04-22: other: Fixes submitted via pull requests 22561 and 22565
  • 2026-05-15: advisory: GitHub Security Advisory published
  • 2026-06-10: disclosed: CVE-2026-46616 published to NVD

References