Code Injection in DotNetNuke - #VU146086

 

Code Injection in DotNetNuke - #VU146086

Published: August 28, 2026


Vulnerability identifier: #VU146086
CSH Severity: Low
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper control of code generation in the theme management functionality when incorporating administrator-supplied content into server-side resources. A remote privileged user can supply crafted content to execute arbitrary code.

Under certain deployment configurations, exploitation can compromise other portals hosted on the same instance.


Affected software

DotNetNuke

Remediation

Install security update from vendor's website.

DotNetNuke - update to 10.3.3

External References

Related Security Bulletins