Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 27 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote unauthenticated attackers to read, modify, or destroy arbitrary database content. The endpoints did not enforce authentication and accepted unsanitized input used in dynamically constructed SQL. The fix in dotCMS Core 26.04.28-03 requires an authenticated backend user with the publishing-queue portlet permission. LTS releases are not affected as the vulnerable code path was never backported. | |
| Title | Unauthenticated SQL Injection in dotCMS Publish Audit API | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dotCMS
Published:
Updated: 2026-05-27T13:40:13.159Z
Reserved: 2026-05-06T19:20:23.237Z
Link: CVE-2026-8054
Updated: 2026-05-27T13:40:09.444Z
Status : Deferred
Published: 2026-05-27T09:16:32.630
Modified: 2026-05-27T19:38:33.270
Link: CVE-2026-8054
No data.
OpenCVE Enrichment
Updated: 2026-05-27T11:15:20Z