๐Ÿ” CVE Alert

CVE-2026-82394

UNKNOWN 0.0

Sulu: Fix authorization bypass when creating preview links

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforce VIEW permission for the target resource in PreviewLinkManager::generate() or PreviewLinkManager::revoke(). An authenticated administration user who knows a target resource identifier can create or revoke a preview link for any page, article, or snippet, including content in a webspace or area the user cannot view. A generated preview URL is public and resolves content by an opaque token, allowing the user or anyone receiving the link to read restricted content without authentication. This issue is fixed in versions 2.6.25 and 3.0.8.

CWE CWE-862 CWE-863
Vendor sulu
Product sulu
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for sulu sulu

Be the first to know when new unknown vulnerabilities affecting sulu sulu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

sulu / sulu
< 2.6.25 >= 3.0.0-alpha1, < 3.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sulu/sulu/security/advisories/GHSA-65cv-w493-7vhq github.com: https://github.com/sulu/sulu/commit/44d8844c3514a70b769ab791b9530df806240fab github.com: https://github.com/sulu/sulu/releases/tag/2.6.25 github.com: https://github.com/sulu/sulu/releases/tag/3.0.8