Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-16337: dotCMS: Low-Privileged User Can Gain Admin Access
CVE-2026-16337
Summary
A low-privileged user can gain admin access to dotCMS and potentially execute arbitrary shell commands. This affects dotCMS versions 21.02 through 26.06.22-03 on all platforms. To fix, update to a patched version of dotCMS or apply the recommended security patches.
Original title
Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to sel...
Original description
Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.
nvd CVSS4.0
9.4
Vulnerability type
CWE-269
Improper Privilege Management
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026