Skip to content
archivevulnerability · 17 Sep 2026 · 16:29 UTC

GHSA-wr57-hqmp-fgvh: Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker

VULNCVE-2026-69197source · GTH
HIGHHigh-risk vulnerability

last 60 dispatches · spectrum

The Content Delivery API enforces member / Public Access protection only at the controller layer, against the node that is directly requested. When a public (unprotected) node references a protected node through a Content Picker or Multi-Node Tree Picker (including those nested inside Block List, Block Grid, or Rich Text Editor blocks), the Delivery API expands and serializes the protected node with no access check applied. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected