An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself.
Metrics
Affected Vendors & Products
References
History
Fri, 02 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:umbraco:umbraco_cms:16.3.3:*:*:*:*:*:*:* |
Fri, 02 Jan 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself. |
Tue, 23 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Umbraco
Umbraco umbraco Umbraco umbraco Cms |
|
| Vendors & Products |
Umbraco
Umbraco umbraco Umbraco umbraco Cms |
Mon, 22 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
Mon, 22 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-02T14:49:08.429Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-67288
Updated: 2025-12-22T18:58:27.475Z
Status : Analyzed
Published: 2025-12-22T19:15:49.710
Modified: 2026-01-02T17:46:24.057
Link: CVE-2025-67288
No data.