An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-54mj-vcvj-q3v5 Umbraco CMS has an arbitrary file upload vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Jan 2026 17:30:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself. The supplier also believes that this CVE is a duplicate of CVE-2023-49279 because the CVEs only differ in the file type. An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.

Thu, 08 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself. An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself. The supplier also believes that this CVE is a duplicate of CVE-2023-49279 because the CVEs only differ in the file type.

Fri, 02 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:umbraco:umbraco_cms:16.3.3:*:*:*:*:*:*:*

Fri, 02 Jan 2026 15:00:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself.

Tue, 23 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Umbraco
Umbraco umbraco
Umbraco umbraco Cms
Vendors & Products Umbraco
Umbraco umbraco
Umbraco umbraco Cms

Mon, 22 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 22 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-08T17:22:20.394Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67288

cve-icon Vulnrichment

Updated: 2025-12-22T18:58:27.475Z

cve-icon NVD

Status : Modified

Published: 2025-12-22T19:15:49.710

Modified: 2026-01-08T18:15:58.790

Link: CVE-2025-67288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-23T22:40:00Z

Weaknesses