PT-2026-97518 · Sulu · Sulu
CVE-2026-92692
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Sulu versions prior to 2.6.25
Sulu versions prior to 3.0.8
Description
Sulu is an open-source PHP content management system based on the Symfony framework. A JCR-SQL2 injection exists in the Smart Content QueryBuilder within
src/Sulu/Component/Content/SmartContent/QueryBuilder.php. The issue occurs because category identifiers provided via the public categories query parameter are concatenated into a JCR-SQL2 WHERE clause without numeric validation. An unauthenticated attacker can exploit this to inject boolean conditions to infer or enumerate content-repository nodes, such as unpublished content, or submit malformed and resource-intensive query fragments that degrade system availability. This flaw allows for the reading and enumeration of nodes but cannot be used to modify repository data.Recommendations
Update Sulu to version 2.6.25 or later.
Update Sulu to version 3.0.8 or later.
As a temporary workaround, disable category filtering on publicly reachable Smart Content elements.
As a temporary workaround, manually cast each ID to an integer where it is concatenated into the category, tag, and audience-targeting WHERE clause in the content Smart Content query builder.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sulu