CVE-2026-46616 Details
Description
Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor templates that derive 'RedirectUrl' from user-controlled query parameters vulnerable to malicious redirect attacks. This issue has been patched in versions 13.14.0 and 17.4.0.
A vulnerability allowing open redirects has been identified in Umbraco CMS versions prior to 13.14.0 and 17.4.0. Some Surface Controllers that handle member-related operations do not properly validate redirect URLs. This oversight allows Razor templates that use 'RedirectUrl' derived from user-controlled query parameters to be exploited for malicious redirect attacks.
Users can upgrade to Umbraco CMS versions 13.14.0 or 17.4.0 to address this vulnerability. If an immediate upgrade is not possible, ensure that all Razor forms posting to 'UmbLoginStatusController', 'UmbProfileController', or 'UmbRegisterController' include a trusted 'RedirectUrl' in the form's route values.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/umbraco/Umbraco-CMS/pull/22561 | [email protected] | Issue TrackingPatch |
| https://github.com/umbraco/Umbraco-CMS/pull/22565 | [email protected] | Issue TrackingPatch |
| https://github.com/umbraco/Umbraco-CMS/security/advisories/GHSA-2qjj-h6wp-c7h7 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| umbraco umbraco cms | < 13.14.0 >= 14.0.0, < 17.4.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | Initial Analysis | [email protected] |
| Jun 10, 2026 | New CVE Received | [email protected] |