CVE-2026-16337 PUBLISHED

Assigner: dotCMS
Reserved: 20.07.2026 Published: 20.07.2026 Updated: 21.07.2026

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor dotCMS
Product dotCMS
Versions Default: unaffected
  • affected from 21.02 to 26.06.22-03 (incl.)

References

Problem Types

  • CWE-269: Improper Privilege Management CWE

Impacts

  • Successful exploitation allows a low-privileged authenticated backend user to escalate to the CMS Administrator role and subsequently achieve remote code execution by uploading a malicious OSGi bundle, resulting in complete compromise of confidentiality, integrity, and availability of the affected instance and any connected infrastructure.