dotCMS Core Publish Audit API - Unauthenticated SQL Injection
CVE-2026-8054
Verified
Description
dotCMS Core 25.11.04-1 through 26.04.28-02 contains an SQL injection caused by unsanitized input in Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll), letting remote unauthenticated attackers read, modify, or destroy arbitrary database content, exploit requires no authentication.
Severity
Critical
Affected Product
dotcms
Published Date
June 9, 2026
Template Author
dhiyaneshdk
CVE-2026-8054.yaml
Remediation Steps
Upgrade to dotCMS Core 26.04.28-03 or later.