Impact
An improper authorization flaw in dotCMS’s ToolGroupResource and RoleAjax endpoints permits a low‑privileged authenticated backend user to assign the administrative layout to themselves and grant the CMS Administrator role. Once elevated, the user can upload a crafted OSGi bundle whose BundleActivator executes arbitrary shell commands, resulting in remote code execution. The core weakness is a privilege escalation scenario (CWE‑269).
Affected Systems
dotCMS dotCMS, versions 21.02 through 26.06.22‑03 on all platforms. Any deployment of dotCMS within this version range is vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 9.4, indicating critical severity. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack scenario requires an authenticated user with limited privileges, followed by the ability to upload an OSGi bundle. If exploited, the attacker can gain full control over the application host by executing arbitrary shell commands.
OpenCVE Enrichment