Incorrect authorization in DotNetNuke - #VU146090

 

Incorrect authorization in DotNetNuke - #VU146090

Published: August 28, 2026


Vulnerability identifier: #VU146090
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to publish unreviewed content and bypass the approval process.

The vulnerability exists due to incorrect authorization in the content workflow when performing workflow state transitions. A remote user can create or edit content and publish their own changes to publish unreviewed content and bypass the approval process.

Only users with permission to create or edit content can exploit this issue.


Affected software

DotNetNuke

Remediation

Install security update from vendor's website.

DotNetNuke - update to 10.3.3

External References

Related Security Bulletins