Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.0.2, the Content Delivery API applies member and Public Access checks to the directly requested node but not to referenced nodes serialized through Content Picker or Multi-Node Tree Picker properties, including pickers nested in Block List, Block Grid, or Rich Text Editor blocks. When DeliveryApi:PublicAccess is enabled, an anonymous caller can retrieve a protected node's name, route, and id through an unprotected referencing node and use ?expand to retrieve full property values. When the Delivery API is instead gated by the organization-wide API key, a key holder can still bypass per-node Public Access through the same expansion path. The same RequestContextOutputExpansionStrategyV2 and ElementOnlyOutputExpansionStrategy path also bypasses allowed or disallowed content-type alias restrictions for referenced content. Direct requests for the protected node still return 401, and no integrity or availability impact is established. This issue is fixed in versions 13.15.1, 17.5.3, and 18.0.2.
CVE-2026-69197
This high-severity CVE scores 8.7 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.7%, top 51% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.7
- EG Score
- 8.7(medium)
- EG Risk
- 54(Track)EG Risk 54/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity87% × 45%Exploitation1% × 40%Automatability100% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 1%
- EPSS %ILE
- 49%
- KEV
- Not listed
Published
September 17, 2026
Last Modified
September 17, 2026
Advisory Details (7)
Auto-updated Sep 17, 202618.0.2
Patch available: umbraco/Umbraco-CMS release-18.0.2
https://github.com/umbraco/Umbraco-CMS/releases/tag/release-18.0.217.5.3
Patch available: umbraco/Umbraco-CMS release-17.5.3
https://github.com/umbraco/Umbraco-CMS/releases/tag/release-17.5.313.15.1
Patch available: umbraco/Umbraco-CMS release-13.15.1
https://github.com/umbraco/Umbraco-CMS/releases/tag/release-13.15.1commit a9649da4e5a0 (umbraco/Umbraco-CMS)
Fix landed in umbraco/Umbraco-CMS commit a9649da4e5a0 — awaiting tagged release
https://github.com/umbraco/Umbraco-CMS/commit/a9649da4e5a0786db7688bd6b5036a21df26b015commit 5360e2a9681c (umbraco/Umbraco-CMS)
Fix landed in umbraco/Umbraco-CMS commit 5360e2a9681c — awaiting tagged release
https://github.com/umbraco/Umbraco-CMS/commit/5360e2a9681ce2d0024be374e80339260bcc2511commit 26312a3f717a (umbraco/Umbraco-CMS)
Fix landed in umbraco/Umbraco-CMS commit 26312a3f717a — awaiting tagged release
https://github.com/umbraco/Umbraco-CMS/commit/26312a3f717a0f33bb3d7d28b14bef3592bdb0feDelivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion · Advisory · umbraco/Umbraco-CMS · GitHub
https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-wr57-hqmp-fgvhVendor Advisories for CVE-2026-69197(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Affected Packages
(1 across 1 ecosystem)
NuGet(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| Umbraco.Cms | 12.0.0 ... 13.9.3 (85 versions) | 13.15.1 | — |
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 11× in last 7d / 15× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-24 15:39 UTCEG score recompute
- 2026-09-24 04:39 UTCEG score recompute
- 2026-09-23 17:54 UTCEPSS rescore
- 2026-09-22 19:38 UTCEG score recompute
- 2026-09-21 21:36 UTCEG score recompute
- 2026-09-21 21:09 UTCEPSS rescore
- 2026-09-20 23:34 UTCEG score recompute
- 2026-09-20 20:16 UTCEPSS rescore
- 2026-09-20 01:32 UTCEG score recompute
- 2026-09-19 03:29 UTCEG score recompute
- 2026-09-18 19:28 UTCEPSS rescore
- 2026-09-17 18:26 UTCEG score recompute
- 2026-09-17 17:56 UTCEG score recompute
- 2026-09-17 15:49 UTCEG score recompute
- 2026-09-17 15:49 UTCMITRE cvelistV5first tracked
Related CVEs(same product + same CWE)
Same product
10 shownNuGet:Umbraco.Cms
Frequently asked(5)
What is CVE-2026-69197?
When was CVE-2026-69197 disclosed?
Is CVE-2026-69197 actively exploited?
What is the CVSS score of CVE-2026-69197?
How do I remediate CVE-2026-69197?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-69197
Is Your Infrastructure Affected by CVE-2026-69197?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.