PT-2026-84047 · Sulu · Sulu

CVE-2026-82395

·

Published

2026-08-31

·

Updated

2026-09-03

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sulu versions prior to 2.6.25 Sulu versions prior to 3.0.8
Description An issue exists in the media move endpoint where permission checks are derived from the client-supplied collection value rather than the actual source collection of the media item. Specifically, the MediaManager::move() function in src/Sulu/Bundle/MediaBundle/Media/Manager/MediaManager.php allows the reassignment of items without verifying the source. An authenticated backend user with edit permissions on one collection and knowledge of a target media identifier can specify an allowed collection in the request to move an item out of a restricted collection, enabling unauthorized viewing or downloading of content.
Recommendations Update to version 2.6.25. Update to version 3.0.8.

Exploit

Fix

IDOR

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82395
GHSA-H6CX-GJXX-V25C

Affected Products

Sulu