CyberSec.Space Logo
Back to CVE Browser

CVE-2026-16337

CRITICAL
9.4
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-20
Last Modified2026-07-22
Data SourcesNVD

Vulnerability Description

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities