๐Ÿ” CVE Alert

CVE-2026-16337

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.

CWE CWE-269
Vendor dotcms
Product dotcms
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for dotcms dotcms

Be the first to know when new unknown vulnerabilities affecting dotcms dotcms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

dotCMS / dotCMS
21.02 โ‰ค 26.06.22-03

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dotCMS/core/pull/36344