CVE-2026-16337
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.
| CWE | CWE-269 |
| Vendor | dotcms |
| Product | dotcms |
| Published | Jul 20, 2026 |
| Last Updated | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for dotcms dotcms
Be the first to know when new unknown vulnerabilities affecting dotcms dotcms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
dotCMS / dotCMS
21.02 โค 26.06.22-03