CVE-2026-24687 | Umbraco Umbraco.Forms.Issues up to 16.4.0/17.1.0 on macOS/Linux Export Endpoint fileName path traversal (GHSA-hm5p-82g6-m3xh / EUVD-2026-4966)
A vulnerability was found in Umbraco Umbraco.Forms.Issues up to 16.4.0/17.1.0 on macOS/Linux. It has been declared as critical. The affected element is an unknown function of the component Export Endpoint. Executing a manipulation of the argument fileName can lead to path traversal.
This vulnerability is handled as CVE-2026-24687. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.