CVE-2026-16337
dotCMS versions 21.02 through 26.06.22‑03 contain a flaw that lets a low‑privileged backend user grant themselves full administrator rights and upload a malicious bundle that runs arbitrary commands on the server. The issue can be triggered remotely without special network access.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
dotCMS 21.02 to 26.06.22‑03 on all platforms. Users with any authenticated backend account but not full admin rights.
Real-world impact
An attacker can elevate themselves to CMS Administrator, then upload a crafted OSGi bundle that executes shell commands, giving them full control over the server.
Why this severity
The CVSS score of 9.4 reflects that the vulnerability is exploitable over the network, requires only low effort and low privilege, and provides complete remote code execution with high impact.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.