Security releaseUmbraco backoffice advisory CVE-2026-41205 — managed clients already patched.Read the advisory
websitesupport.io
All articles
SecurityUmbracoAdvisory

Umbraco backoffice authentication bypass — what managed clients need to know

A critical flaw (CVE-2026-41205) in the Umbraco backoffice authentication flow could allow session hijacking. Managed clients were patched immediately.

W
WebsiteSupport.io Security Team
24 Jul 20264 min read
CVE-2026-41205
Advisory

CVE-2026-41205 · Critical · Umbraco 13–14 · Upgrade and rotate backoffice sessions immediately.

On 24 July 2026, a critical authentication flaw was disclosed affecting the Umbraco backoffice on versions 13 and 14. Under specific hosting configurations, a crafted request to the backoffice authentication endpoint could allow an attacker to hijack an active editor or administrator session without knowing their password.

Every managed client on our Umbraco support retainer was patched and had backoffice sessions rotated before this became public knowledge. We monitor the .NET and Umbraco security channels continuously and maintain tested patching runbooks for every version we support.

What is the vulnerability?

The flaw sits in how the backoffice validates session cookies behind a reverse proxy or load balancer — a very common production setup for Umbraco. Under certain header-forwarding configurations, a session token issued to one user could be replayed by an attacker to impersonate that session, including on privileged administrator accounts.

The Umbraco security team rates this Critical. Exploitation requires network access to the backoffice URL and knowledge of the specific proxy misconfiguration — not trivial, but well within reach of automated scanning once the advisory details circulate publicly.

Affected versions

  • Umbraco 13.x — patch to 13.5.2
  • Umbraco 14.x — patch to 14.2.1
  • Umbraco 12.x and earlier are not affected by this specific flaw, but are end-of-life and should be upgraded regardless
  • Umbraco Cloud environments were patched centrally; self-hosted instances must update manually

What you should do right now

If you are on a WebsiteSupport.io managed Umbraco retainer: nothing further — you are already patched and every backoffice session was force-rotated. If you manage your own Umbraco instance, update immediately and force all editors to log in again.

  • Update to the patched Umbraco version for your major release
  • Force-expire all existing backoffice sessions after patching
  • Review your reverse proxy / load balancer configuration for correct forwarded-header handling
  • Audit the backoffice user list and content log for any unfamiliar activity in the last two weeks

How we handled this for managed clients

We received early notification through our .NET security monitoring on 22 July, tested the patch across our Umbraco 13 and 14 staging environments, and confirmed no regressions against our clients' custom packages. Patches were deployed to every managed production instance on 23 July, a day ahead of the public advisory — inside our Critical SLA.

On a self-managed Umbraco site?

We offer a one-off emergency patching service for teams that need help applying this update quickly. Get in touch and we can usually turn this around within a few hours.

Stay ahead of the next release

Security alerts, platform updates and industry analysis — straight to your inbox.

We respect your privacy and only send essential updates.