PT-2026-97518 · Sulu · Sulu

CVE-2026-92692

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sulu versions prior to 2.6.25 Sulu versions prior to 3.0.8
Description Sulu is an open-source PHP content management system based on the Symfony framework. A JCR-SQL2 injection exists in the Smart Content QueryBuilder within src/Sulu/Component/Content/SmartContent/QueryBuilder.php. The issue occurs because category identifiers provided via the public categories query parameter are concatenated into a JCR-SQL2 WHERE clause without numeric validation. An unauthenticated attacker can exploit this to inject boolean conditions to infer or enumerate content-repository nodes, such as unpublished content, or submit malformed and resource-intensive query fragments that degrade system availability. This flaw allows for the reading and enumeration of nodes but cannot be used to modify repository data.
Recommendations Update Sulu to version 2.6.25 or later. Update Sulu to version 3.0.8 or later. As a temporary workaround, disable category filtering on publicly reachable Smart Content elements. As a temporary workaround, manually cast each ID to an integer where it is concatenated into the category, tag, and audience-targeting WHERE clause in the content Smart Content query builder.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92692
GHSA-JG26-Q8HG-3PQ4

Affected Products

Sulu