Junglewise Threat Intelligence

CVE-2026-16337: dotCMS privilege escalation and RCE in ToolGroupResource and RoleAjax

CVE-2026-16337 · Severity: info · CVSS 9.4 · Published 2026-07-20

Technologies: dotCMS. Vendors: dotCMS.

Executive brief

A vulnerability in dotCMS allows a user with low-level access to the system's backend to escalate their privileges to a full administrator. By exploiting flaws in how the system manages user layouts and roles, an attacker can grant themselves administrative rights and then execute arbitrary commands on the underlying server. This could lead to a complete takeover of the CMS, theft of sensitive data, or a total service outage.

Technical details

A privilege escalation chain exists in the ToolGroupResource and RoleAjax REST/DWR endpoints. An authenticated backend user can first exploit an authorization bypass in the 'ToolGroupResource._addtouser' endpoint to self-assign the administrative 'Settings' layout. Once the layout is assigned, the attacker can access the roles portlet and exploit a second authorization flaw in 'RoleAjax.addUserToRole' to grant themselves the 'CMS Administrator' role. With administrative privileges, the attacker can achieve remote code execution by uploading a malicious OSGi bundle whose BundleActivator executes shell commands. The fix involves enforcing strict 'isAdmin()' checks on these endpoints, while maintaining an exemption for the 'gettingStarted' onboarding layout.

Affected products

  • dotCMS dotCMS 21.02 through 26.06.22-03

Timeline

  • 2026-06-28: other: Fix submitted via pull request
  • 2026-07-15: patched: Fix merged into main branch
  • 2026-07-20: disclosed: CVE published

References

Related threats