Keywords: Umbraco Forms vulnerability, Forms security patch, 13.9.8, 17.4.7, 18.0.5, form submission bypass, high severity, security advisory
Product: Umbraco Forms
Affected versions: 13.0.0 - 13.9.7, 17.0.0 - 17.4.6, 18.0.0 - 18.0.4
Severity: High
Status: Patch available
Overview
A vulnerability classified as high has been found and fixed in Umbraco Forms. Patches were released on July 28, 2026 for versions 13, 17, and 18. If you run an affected version, we recommend upgrading.
Who's affected
You're affected if your site runs one of these Umbraco Forms versions:
Umbraco Forms 13.0.0 - 13.9.7
Umbraco Forms 17.0.0 - 17.4.6
Umbraco Forms 18.0.0 - 18.0.4
Unsupported versions can also be subject to the vulnerability, but will not receive a patch. If you're on an unsupported major and using the affected features, upgrade to a supported major version.
What we know about the vulnerability
A flaw in how Umbraco Forms handled form submissions allowed the multi-page progression to be manipulated, so the server treated a form as complete too early. An unauthenticated user could finalise a submission without completing the intended flow.
Server-side validation checks that normally run before a submission is accepted could be bypassed, and a form could be submitted in an incomplete or unverified state. Post-submission actions such as configured workflows could still be triggered. This affects both single-page and multi-page forms.
The severity is rated High: remotely exploitable by an unauthenticated user, reliably reproducible, and it bypasses submission safeguards while still storing a submission and triggering downstream actions.
What to do
If you're on Umbraco Cloud
No action needed. An automatic upgrade was rolled out on July 28, 2026.
Note that auto-upgrades roll out per environment, so you may briefly see different versions across Development, Staging, and Live. See Delayed Environment Auto-Upgrades on Umbraco Cloud.
If you're self-hosted
Upgrade to the patched version for your major:
Upgrade the way you normally would. These are patch releases, so no breaking changes are expected.
Not sure which version you're on?
Send this article, or the security advisory blog post, to the technical contact for your Umbraco site. They can check the version and handle the upgrade.
Credit
Thanks to Ismael Machuca for reporting the issue and for responsible disclosure.
Questions or reporting a security issue
For questions about this advisory, use the dedicated security email address on umbraco.com/security. That page also explains how we handle security issues.
To get future advisories directly, sign up for the security mailing list.
Related articles
Last updated in July 28, 2026
