PT-2026-84041 · Sulu · Sulu
CVE-2026-82394
·
Published
2026-08-31
·
Updated
2026-09-02
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Sulu versions prior to 2.6.25
Sulu versions prior to 3.0.8
Description
An issue exists in the preview-link endpoint and the
src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php file where VIEW permissions are not enforced for the target resource within the generate() and revoke() functions of PreviewLinkManager. An authenticated administration user with knowledge of a target resource identifier can create or revoke preview links for any page, article, or snippet, regardless of whether they have access to the associated webspace or area. Because generated preview URLs are public and use an opaque token to resolve content, they allow the user or any recipient of the link to access restricted content without authentication.Recommendations
Update Sulu to version 2.6.25 or later.
Update Sulu to version 3.0.8 or later.
Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sulu