SB2026082864 - Multiple vulnerabilities in DotNetNuke



SB2026082864 - Multiple vulnerabilities in DotNetNuke

Published: August 28, 2026

Security Bulletin ID SB2026082864
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 9
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 22% Low 78%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 9 vulnerabilities.


1) Cross-site scripting (CVE-ID: N/A)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary JavaScript in the victim\'s browser.

The vulnerability exists due to cross-site scripting (XSS) in the HTML module when storing HTML content with embedded JavaScript. A remote user can submit crafted HTML module content to execute arbitrary JavaScript in the victim\'s browser.

This issue affects environments where content editing permissions are granted to users who are not fully trusted.


2) Code Injection (CVE-ID: N/A)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper control of code generation in the theme management functionality when incorporating administrator-supplied content into server-side resources. A remote privileged user can supply crafted content to execute arbitrary code.

Under certain deployment configurations, exploitation can compromise other portals hosted on the same instance.


3) Authorization bypass through user-controlled key (CVE-ID: N/A)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass administrative approval for pending user registrations.

The vulnerability exists due to improper access control in the user registration approval process when handling registration approval actions. A remote user can approve pending user accounts to bypass administrative approval for pending user registrations.

This issue affects sites that use administrator approval for new user registrations.


4) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to interact with private journal posts without authorization.

The vulnerability exists due to missing authorization in the Journal module when recording likes on private journal posts. A remote user can add a like to a private journal entry they are not authorized to access to interact with private journal posts without authorization.

The issue does not expose the contents of private journal posts or allow modification of their content, but it may create visible interactions associated with private activity.


5) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to publish unreviewed content and bypass the approval process.

The vulnerability exists due to incorrect authorization in the content workflow when performing workflow state transitions. A remote user can create or edit content and publish their own changes to publish unreviewed content and bypass the approval process.

Only users with permission to create or edit content can exploit this issue.


6) Authorization bypass through user-controlled key (CVE-ID: N/A)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify another group\'s information.

The vulnerability exists due to authorization bypass through user-controlled key in the Social Groups module GroupEdit functionality when processing tampered postback data during group management operations. A remote user can submit a tampered postback request to modify another group\'s information.

Successful exploitation can result in unauthorized changes to editable group information and may be used to publish misleading content that appears to originate from legitimate group owners or administrators.


7) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to perform unauthorized administrative actions within affected modules.

The vulnerability exists due to incorrect authorization in the permission evaluation logic when evaluating module permissions in the presence of broader page-level permissions. A remote privileged user can use page-level content management permissions to access module administration features and perform unauthorized administrative actions within affected modules.

User interaction is required.


8) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause the server to initiate requests to arbitrary network resources.

The vulnerability exists due to server-side request forgery (ssrf) in the Journal module link preview functionality when processing user-supplied URLs. A remote user can supply a crafted URL to cause the server to initiate requests to arbitrary network resources.

Depending on the deployment environment, exploitation may allow access to network resources that are not directly reachable from the Internet.


9) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to missing authorization in the file management functionality when retrieving file information from restricted folders. A remote attacker can request file names and related metadata from folders they are not authorized to browse to disclose sensitive information.

The issue does not expose file contents, but it can reveal file names and metadata associated with otherwise inaccessible resources.


Remediation

Install update from vendor's website.