THREAT OPS › Threat News › [GHSA] GHSA-wr57-hqmp-fgvh (high) — Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
[GHSA] GHSA-wr57-hqmp-fgvh (high) — Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
GHSA-wr57-hqmp-fgvh Severity: high CVE: CVE-2026-69197
Umbraco: Delivery API leaks protected (Public Access) content through Content Picker / Multi-Node Tree Picker expansion
The Content Delivery API enforces member / Public Access protection only at the controller layer, against the node that is directly requested. When a public (unprotected) node references a protected node through a Content P
Indicators of compromise
- CVE-2026-69197cve
- https://docs.umbraco.com/umbraco-cms/develop-with-umbraco/headless-and-apis/content-delivery-apiurl
Original source: https://github.com/advisories/GHSA-wr57-hqmp-fgvh