vulns.co
/
GKData.io MCP

GitHub Security Lab · 1 min read

Umbraco: editing an account does not authorize assigning every role

CVE-2026-31834 separates authority over an account from authority to grant its roles. Research on Umbraco CMS 17.2.0 found that group-membership changes checked access to target users but omitted restrictions applied by the ordinary user-editing flow. A qualifying non-administrator API account could obtain administrator membership.

Open the reference Research PaperReviewed 2026-10-03

How to use this reference

Editorial lesson: model both the target account and the proposed privilege as authorization inputs, using consistent policy across bulk and individual operations. The maintainer confirms the role-assignment defect and fixes in 16.5.1 and 17.2.2; upgrade affected installations rather than relying on interface restrictions.

Before reading

  • Basic server-side authorization concepts

Context and limits

  • Requires an authenticated backoffice API user with access to the Users section. The vendor notes that this is ordinarily restricted to administrators, making custom delegation important to exposure.
  • The research reports administrator membership; the vendor describes resulting administrative control. Neither source establishes a customer incident or exploitation prevalence.
  • Research reported February 25, 2026; acknowledged as a duplicate the next day. The vendor advisory was published March 10; detailed research September 21.
  • The maintainer lists affected versions as >=15.3.1, <17.2.1, while listing 16.5.1 and 17.2.2 as patched. These fields conflict; no corrected affected interval is inferred.
  • The byline is Jaroslav Lobačevski; discovery is credited to the GitHub Security Lab Taskflow Agent with his manual verification. The maintainer credits odgrso separately. Learning prerequisites are editorial.

Sources and provenance

  1. GHSL-2026-065: Unauthorized group assignment enables privilege escalation in Umbraco CMS GitHub Security Lab · reviewed 2026-10-03
  2. Vertical Privilege Escalation via Missing Authorization Checks Umbraco · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software