CVE-2026-31834 | Umbraco CMS up to 16.5.0/17.2.1 Group Membership privileges management (GHSA-rhcg-3h8r-v6vp)
A vulnerability has been found in Umbraco CMS up to 16.5.0/17.2.1 and classified as critical. This vulnerability affects unknown code of the component Group Membership Handler. Performing a manipulation results in improper privilege management.
This vulnerability is cataloged as CVE-2026-31834. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.