PT-2026-84041 · Sulu · Sulu

CVE-2026-82394

·

Published

2026-08-31

·

Updated

2026-09-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sulu versions prior to 2.6.25 Sulu versions prior to 3.0.8
Description An issue exists in the preview-link endpoint and the src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php file where VIEW permissions are not enforced for the target resource within the generate() and revoke() functions of PreviewLinkManager. An authenticated administration user with knowledge of a target resource identifier can create or revoke preview links for any page, article, or snippet, regardless of whether they have access to the associated webspace or area. Because generated preview URLs are public and use an opaque token to resolve content, they allow the user or any recipient of the link to access restricted content without authentication.
Recommendations Update Sulu to version 2.6.25 or later. Update Sulu to version 3.0.8 or later.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82394
GHSA-65CV-W493-7VHQ

Affected Products

Sulu