/Vulnerability Library

dotCMS Core Publish Audit API - Unauthenticated SQL Injection

CVE-2026-8054
Verified

Description

dotCMS Core 25.11.04-1 through 26.04.28-02 contains an SQL injection caused by unsanitized input in Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll), letting remote unauthenticated attackers read, modify, or destroy arbitrary database content, exploit requires no authentication.

Severity

Critical

Affected Product

dotcms

Published Date

June 9, 2026

Template Author

dhiyaneshdk

CVE-2026-8054.yaml
9.5Severity

CVSS Metrics

References

https://github.com/advisories/GHSA-jpx3-25r2-jq5ghttps://github.com/dotCMS/core/pull/35553https://dev.dotcms.com/docs/known-security-issues?issueNumber=SI-75

Remediation Steps

Upgrade to dotCMS Core 26.04.28-03 or later.