Umbraco backoffice authentication bypass — what managed clients need to know
A critical flaw (CVE-2026-41205) in the Umbraco backoffice authentication flow could allow session hijacking. Managed clients were patched immediately.
CVE-2026-41205 · Critical · Umbraco 13–14 · Upgrade and rotate backoffice sessions immediately.
On 24 July 2026, a critical authentication flaw was disclosed affecting the Umbraco backoffice on versions 13 and 14. Under specific hosting configurations, a crafted request to the backoffice authentication endpoint could allow an attacker to hijack an active editor or administrator session without knowing their password.
Every managed client on our Umbraco support retainer was patched and had backoffice sessions rotated before this became public knowledge. We monitor the .NET and Umbraco security channels continuously and maintain tested patching runbooks for every version we support.
What is the vulnerability?
The flaw sits in how the backoffice validates session cookies behind a reverse proxy or load balancer — a very common production setup for Umbraco. Under certain header-forwarding configurations, a session token issued to one user could be replayed by an attacker to impersonate that session, including on privileged administrator accounts.
The Umbraco security team rates this Critical. Exploitation requires network access to the backoffice URL and knowledge of the specific proxy misconfiguration — not trivial, but well within reach of automated scanning once the advisory details circulate publicly.
Affected versions
- Umbraco 13.x — patch to 13.5.2
- Umbraco 14.x — patch to 14.2.1
- Umbraco 12.x and earlier are not affected by this specific flaw, but are end-of-life and should be upgraded regardless
- Umbraco Cloud environments were patched centrally; self-hosted instances must update manually
What you should do right now
If you are on a WebsiteSupport.io managed Umbraco retainer: nothing further — you are already patched and every backoffice session was force-rotated. If you manage your own Umbraco instance, update immediately and force all editors to log in again.
- Update to the patched Umbraco version for your major release
- Force-expire all existing backoffice sessions after patching
- Review your reverse proxy / load balancer configuration for correct forwarded-header handling
- Audit the backoffice user list and content log for any unfamiliar activity in the last two weeks
How we handled this for managed clients
We received early notification through our .NET security monitoring on 22 July, tested the patch across our Umbraco 13 and 14 staging environments, and confirmed no regressions against our clients' custom packages. Patches were deployed to every managed production instance on 23 July, a day ahead of the public advisory — inside our Critical SLA.
We offer a one-off emergency patching service for teams that need help applying this update quickly. Get in touch and we can usually turn this around within a few hours.
Related articles
Webflow tightens Marketplace review after malicious embed apps found injecting scripts
A wave of third-party Webflow Marketplace apps were found injecting obfuscated scripts via legitimate-looking embeds. Here's what happened and what to check on your own site.
8 Aug 2026 · 4 min readPlatform updatesUmbraco 15 arrives — what enterprise and public-sector teams should plan for
The latest major Umbraco release brings backoffice and performance improvements. Here's what matters if you're running an older version.
24 Jun 2026 · 4 min readSecurityCritical access-bypass patched in Drupal core
A significant vulnerability (SA-CORE-2026-008) affecting Drupal 10.3–11.1. Managed clients were patched within the SLA window.
30 May 2026 · 3 min readStay ahead of the next release
Security alerts, platform updates and industry analysis — straight to your inbox.