An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-54mj-vcvj-q3v5 Umbraco CMS has an arbitrary file upload vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 09 Jan 2026 02:30:00 +0900

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself. The supplier also believes that this CVE is a duplicate of CVE-2023-49279 because the CVEs only differ in the file type. An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself, a related issue to CVE-2023-49279.

Fri, 09 Jan 2026 01:15:00 +0900

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself. An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself. The supplier also believes that this CVE is a duplicate of CVE-2023-49279 because the CVEs only differ in the file type.

Sat, 03 Jan 2026 03:00:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:umbraco:umbraco_cms:16.3.3:*:*:*:*:*:*:*

Sat, 03 Jan 2026 00:00:00 +0900

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself.

Wed, 24 Dec 2025 08:00:00 +0900

Type Values Removed Values Added
First Time appeared Umbraco
Umbraco umbraco
Umbraco umbraco Cms
Vendors & Products Umbraco
Umbraco umbraco
Umbraco umbraco Cms

Tue, 23 Dec 2025 04:15:00 +0900

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 23 Dec 2025 03:30:00 +0900

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-08T17:22:20.394Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67288

cve-icon Vulnrichment

Updated: 2025-12-22T18:58:27.475Z

cve-icon NVD

Status : Modified

Published: 2025-12-22T19:15:49.710

Modified: 2026-01-08T18:15:58.790

Link: CVE-2025-67288

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-24T07:40:00Z

Weaknesses