CVE-2026-24687 is a low severity vulnerability with a CVSS score of 0.0. No known exploits currently, and patches are available.
Very low probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
It's possible for an authenticated backoffice-user to enumerate and traverse paths/files on the systems filesystem and read their contents, on Mac/Linux Umbraco installations using Forms. As Umbraco Cloud runs in a Windows environment, Cloud users aren't affected.
This issue affects versions 16 and 17 of Umbraco Forms and is patched in 16.4.1 and 17.1.1
If upgrading is not immediately possible, users can mitigate this vulnerability by:
../, ..\) in the fileName parameter of the export endpoint/umbraco/forms/api/v1/export endpoint entirely if the export feature is not requiredHowever, upgrading to the patched version is strongly recommended.
Credit to Kevin Joensen from Baldur Security for finding this vulnerability
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.