SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-16337

CRITICAL · CVSS 9.4 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Improper authorization vulnerabilities in the ToolGroupResource and RoleAjax REST/DWR endpoints of dotCMS versions 21.02 through 26.06.22-03 allow low-privileged authenticated backend users to self-assign administrative roles and execute arbitrary shell commands through crafted OSGi bundle uploads. This could lead to remote code execution, posing significant risks to the integrity and security of the affected systems. Organizations using these versions of dotCMS should prioritize remediation to prevent potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-16337
Severity
CRITICAL
CVSS
9.4
EPSS
0.40%

Original NVD Description

Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.