216.73.216.226

CVE-2025-11165

· Published 24/02/2026 09:16 · Modified 24/02/2026 14:13

Labels: CVE-2025-11165 2026-02-24CVE-2025-11165CWE-89[email protected]

Essential information

Published
24/02/2026 09:16
Modified
24/02/2026 14:13
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A sandbox escape vulnerability exists in dotCMS’s Velocity scripting engine (VTools) that allows authenticated users with scripting privileges to bypass class and package restrictions enforced by SecureUberspectorImpl. By dynamically modifying the Velocity engine’s runtime configuration and reinitializing its Uberspect, a malicious actor can remove the introspector.restrict.classes and introspector.restrict.packages protections. Once these restrictions are cleared, the attacker can access arbitrary Java classes, including java.lang.Runtime, and execute arbitrary system commands under the privileges of the application process (e.g. dotCMS or Tomcat user).

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dotcms / dotcms cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*
dotcms / velocity cpe:2.3:a:dotcms:velocity:*:*:*:*:*:*:*:*

References