{"id":"CVE-2026-24687","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-24687","summary":"Umbraco.Forms has Path Traversal and File Enumeration Vulnerabilities in Linux/Mac","details":"### Impact\nIt's possible for an authenticated backoffice-user to enumerate and traverse paths/files on the systems filesystem and read their contents, on Mac/Linux Umbraco installations using Forms. As Umbraco Cloud runs in a Windows environment, Cloud users aren't affected. \n\n### Patches\nThis issue affects versions 16 and 17 of Umbraco Forms and is patched in 16.4.1 and 17.1.1\n\n### Workarounds\nIf upgrading is not immediately possible, users can mitigate this vulnerability by:\n* Configuring a WAF or reverse proxy to block requests containing path traversal sequences (`../`, `..\\`) in the `fileName` parameter of the export endpoint\n* Restricting network access to the Umbraco backoffice to trusted IP ranges\n* Blocking the `/umbraco/forms/api/v1/export` endpoint entirely if the export feature is not required\n\nHowever, upgrading to the patched version is strongly recommended.\n\n### References\nCredit to Kevin Joensen from Baldur Security for finding this vulnerability","published":"2026-01-30T14:43:18Z","modified":"2026-02-03T03:12:28.668803Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Umbraco.Forms","fixedVersion":"16.4.1"},{"ecosystem":"NuGet","name":"Umbraco.Forms","fixedVersion":"17.1.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/umbraco/Umbraco.Forms.Issues/security/advisories/GHSA-hm5p-82g6-m3xh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24687"},{"type":"PACKAGE","url":"https://github.com/umbraco/Umbraco.Forms.Issues"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-03T03:12:28.668803Z"}}