Improper Authorization in dotCMS by dotCMS
CVE-2026-16337
9.4CRITICAL
What is CVE-2026-16337?
The vulnerability in dotCMS versions 21.02 to 26.06.22-03 allows low-privileged authenticated users to exploit improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints. This enables them to self-assign administrative layout privileges and grant themselves the CMS Administrator role, ultimately leading to remote code execution via crafted OSGi bundle uploads. Executing arbitrary shell commands becomes possible, posing a significant risk to the security of affected installations.
Affected Version(s)
dotCMS 21.02 <= 26.06.22-03
