Skip to main content

Security patch for Umbraco Forms 13, 17, and 18 (July 28, 2026)

Keywords: Umbraco Forms vulnerability, Forms security patch, 13.9.8, 17.4.7, 18.0.5, form submission bypass, high severity, security advisory

Written by Joana Knobbe

Keywords: Umbraco Forms vulnerability, Forms security patch, 13.9.8, 17.4.7, 18.0.5, form submission bypass, high severity, security advisory

Product: Umbraco Forms
Affected versions: 13.0.0 - 13.9.7, 17.0.0 - 17.4.6, 18.0.0 - 18.0.4
Severity: High
Status: Patch available

Overview

A vulnerability classified as high has been found and fixed in Umbraco Forms. Patches were released on July 28, 2026 for versions 13, 17, and 18. If you run an affected version, we recommend upgrading.

Who's affected

You're affected if your site runs one of these Umbraco Forms versions:

  • Umbraco Forms 13.0.0 - 13.9.7

  • Umbraco Forms 17.0.0 - 17.4.6

  • Umbraco Forms 18.0.0 - 18.0.4

Unsupported versions can also be subject to the vulnerability, but will not receive a patch. If you're on an unsupported major and using the affected features, upgrade to a supported major version.

What we know about the vulnerability

A flaw in how Umbraco Forms handled form submissions allowed the multi-page progression to be manipulated, so the server treated a form as complete too early. An unauthenticated user could finalise a submission without completing the intended flow.

Server-side validation checks that normally run before a submission is accepted could be bypassed, and a form could be submitted in an incomplete or unverified state. Post-submission actions such as configured workflows could still be triggered. This affects both single-page and multi-page forms.

The severity is rated High: remotely exploitable by an unauthenticated user, reliably reproducible, and it bypasses submission safeguards while still storing a submission and triggering downstream actions.


What to do

If you're on Umbraco Cloud

No action needed. An automatic upgrade was rolled out on July 28, 2026.

Note that auto-upgrades roll out per environment, so you may briefly see different versions across Development, Staging, and Live. See Delayed Environment Auto-Upgrades on Umbraco Cloud.

If you're self-hosted

Upgrade to the patched version for your major:

Upgrade the way you normally would. These are patch releases, so no breaking changes are expected.

Not sure which version you're on?

Send this article, or the security advisory blog post, to the technical contact for your Umbraco site. They can check the version and handle the upgrade.


Credit

Thanks to Ismael Machuca for reporting the issue and for responsible disclosure.

Questions or reporting a security issue

For questions about this advisory, use the dedicated security email address on umbraco.com/security. That page also explains how we handle security issues.

To get future advisories directly, sign up for the security mailing list.

Related articles


Last updated in July 28, 2026

Did this answer your question?