An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself.
History

Fri, 02 Jan 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:umbraco:umbraco_cms:16.3.3:*:*:*:*:*:*:*

Fri, 02 Jan 2026 15:00:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file. An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself.

Tue, 23 Dec 2025 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Umbraco
Umbraco umbraco
Umbraco umbraco Cms
Vendors & Products Umbraco
Umbraco umbraco
Umbraco umbraco Cms

Mon, 22 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 22 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
Description An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-02T14:49:08.429Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67288

cve-icon Vulnrichment

Updated: 2025-12-22T18:58:27.475Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-22T19:15:49.710

Modified: 2026-01-02T17:46:24.057

Link: CVE-2025-67288

cve-icon Redhat

No data.