How to use this reference
Editorial lesson: model both the target account and the proposed privilege as authorization inputs, using consistent policy across bulk and individual operations. The maintainer confirms the role-assignment defect and fixes in 16.5.1 and 17.2.2; upgrade affected installations rather than relying on interface restrictions.
Before reading
- Basic server-side authorization concepts
Context and limits
- Requires an authenticated backoffice API user with access to the Users section. The vendor notes that this is ordinarily restricted to administrators, making custom delegation important to exposure.
- The research reports administrator membership; the vendor describes resulting administrative control. Neither source establishes a customer incident or exploitation prevalence.
- Research reported February 25, 2026; acknowledged as a duplicate the next day. The vendor advisory was published March 10; detailed research September 21.
- The maintainer lists affected versions as >=15.3.1, <17.2.1, while listing 16.5.1 and 17.2.2 as patched. These fields conflict; no corrected affected interval is inferred.
- The byline is Jaroslav Lobačevski; discovery is credited to the GitHub Security Lab Taskflow Agent with his manual verification. The maintainer credits odgrso separately. Learning prerequisites are editorial.
Sources and provenance
- GHSL-2026-065: Unauthorized group assignment enables privilege escalation in Umbraco CMS GitHub Security Lab · reviewed 2026-10-03
- Vertical Privilege Escalation via Missing Authorization Checks Umbraco · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.