CVE-2026-27449 details a critical broken access control vulnerability in Umbraco Engage versions prior to 16.2.1 and 17.1.1. Unauthenticated attackers can directly access certain API endpoints over the network, bypassing authentication and authorization checks. By manipulating an identifier parameter, attackers can enumerate and retrieve sensitive Engage-related data, such as analytics, tracking, or customer information, leading to a high confidentiality impact. The CVSS score is 7.5 (High), indicating a network-exploitable vulnerability with low attack complexity and no user interaction required. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Umbraco | Umbraco.Engage.Forms | < 16.2.1, >= 17.0.0, < 17.1.1CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.