Access Control Weakness in Sulu CMS by Sulu
CVE-2026-34372

5.3MEDIUM

Key Information:

Vendor

Sulu

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34372?

Sulu, an open-source PHP content management system built on the Symfony framework, has revealed an access control vulnerability. This issue allows users with admin privileges to access sub-entities related to contacts through the admin API, even without explicit permissions for those contact entities. This flawed access control affects Sulu versions prior to 2.6.22 and 3.0.5, highlighting the importance of regular updates to maintain robust security. The vulnerability has been addressed in the latest updates, urging users to upgrade to secure their systems.

Affected Version(s)

sulu >= 1.0.0, < 2.6.22 < 1.0.0, 2.6.22

sulu >= 3.0.0, < 3.0.5 < 3.0.0, 3.0.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.