Access Control Vulnerability in Sulu CMS by Sulu
CVE-2026-82394
What is CVE-2026-82394?
Sulu CMS, an open-source PHP content management system built on the Symfony framework, contains a vulnerability where the preview-link endpoint does not properly enforce VIEW permissions for target resources in critical functions. This oversight allows authenticated administration users to generate or revoke preview links for any page, article, or snippet, including ones restricted to certain users. The publicly accessible preview URLs reveal content using an opaque token, potentially exposing confidential information to unauthorized users. This vulnerability was addressed in versions 2.6.25 and 3.0.8, and all users are recommended to update to these versions to mitigate risks.
Affected Version(s)
sulu < 2.6.25 < 2.6.25
sulu >= 3.0.0-alpha1, < 3.0.8 < 3.0.0-alpha1, 3.0.8
