CVE-2026-8054
dotCMS vulnerability analysis and mitigation

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote unauthenticated attackers to read, modify, or destroy arbitrary database content. The endpoints did not enforce authentication and accepted unsanitized input used in dynamically constructed SQL. The fix in dotCMS Core 26.04.28-03 requires an authenticated backend user with the publishing-queue portlet permission. LTS releases are not affected as the vulnerable code path was never backported.


SourceNVD

Related dotCMS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8054CRITICAL10
  • dotCMS logodotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesMay 27, 2026
CVE-2026-16337CRITICAL9.4
  • dotCMS logodotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesJul 20, 2026
CVE-2025-11165CRITICAL9.4
  • dotCMS logodotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesFeb 24, 2026
CVE-2024-3938MEDIUM6.1
  • dotCMS logodotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesJul 25, 2024
CVE-2024-3165MEDIUM4.5
  • dotCMS logodotCMS
  • cpe:2.3:a:dotcms:dotcms
NoYesApr 01, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management