PT-2026-84047 · Sulu · Sulu
CVE-2026-82395
·
Published
2026-08-31
·
Updated
2026-09-03
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Sulu versions prior to 2.6.25
Sulu versions prior to 3.0.8
Description
An issue exists in the media move endpoint where permission checks are derived from the client-supplied collection value rather than the actual source collection of the media item. Specifically, the
MediaManager::move() function in src/Sulu/Bundle/MediaBundle/Media/Manager/MediaManager.php allows the reassignment of items without verifying the source. An authenticated backend user with edit permissions on one collection and knowledge of a target media identifier can specify an allowed collection in the request to move an item out of a restricted collection, enabling unauthorized viewing or downloading of content.Recommendations
Update to version 2.6.25.
Update to version 3.0.8.
Exploit
Fix
IDOR
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sulu