Executive brief
dotCMS, a content management system used to power corporate websites and applications, contains a critical vulnerability in its Publish Audit API. This flaw allows an unauthenticated attacker to remotely access or modify the underlying database without a password. Successful exploitation could lead to the theft of sensitive customer data, unauthorized modification of website content, or the complete destruction of database records.
Technical details
A SQL injection vulnerability exists in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) of dotCMS Core. The root cause is the improper neutralization of the 'bundle-id' parameter within the getPublishAuditStatuses method, where input was manually wrapped in single quotes and formatted into a dynamic SQL IN clause without parameterization. Because these endpoints did not enforce authentication, a remote attacker can execute arbitrary SQL commands against the backend database. The vulnerability is fixed in version 26.04.28-03 by implementing parameterized queries and enforcing backend user permissions. LTS releases are reportedly unaffected.
Affected products
- dotCMS dotCMS Core 25.11.04-1 through 26.04.28-02
Timeline
- 2026-05-04: patched: Pull request to parameterize queries merged into main branch.
- 2026-05-27: advisory: CVE-2026-8054 published.