Incorrect authorization in DotNetNuke - #VU146090
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to publish unreviewed content and bypass the approval process.
The vulnerability exists due to incorrect authorization in the content workflow when performing workflow state transitions. A remote user can create or edit content and publish their own changes to publish unreviewed content and bypass the approval process.
Only users with permission to create or edit content can exploit this issue.