CVE-2026-16337

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.
CVSS

No CVSS.

Configurations

No configuration.

History

20 Jul 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 20:16

Updated : 2026-07-22 20:37


NVD link : CVE-2026-16337

Mitre link : CVE-2026-16337

CVE.ORG link : CVE-2026-16337


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management