Access Control Vulnerability in Sulu CMS by Sulu
CVE-2026-82394

5.3MEDIUM

Key Information:

Vendor

Sulu

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82394?

Sulu CMS, an open-source PHP content management system built on the Symfony framework, contains a vulnerability where the preview-link endpoint does not properly enforce VIEW permissions for target resources in critical functions. This oversight allows authenticated administration users to generate or revoke preview links for any page, article, or snippet, including ones restricted to certain users. The publicly accessible preview URLs reveal content using an opaque token, potentially exposing confidential information to unauthorized users. This vulnerability was addressed in versions 2.6.25 and 3.0.8, and all users are recommended to update to these versions to mitigate risks.

Affected Version(s)

sulu < 2.6.25 < 2.6.25

sulu >= 3.0.0-alpha1, < 3.0.8 < 3.0.0-alpha1, 3.0.8

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.