๐Ÿ” CVE Alert

CVE-2026-82395

UNKNOWN 0.0

Sulu: Media move/update authorization bypass (IDOR)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media item's actual source collection, and src/Sulu/Bundle/MediaBundle/Media/Manager/MediaManager.php allows MediaManager::move() to reassign the item without checking that source. An authenticated backend user with edit permission on one collection and knowledge of a target media identifier can name the allowed collection in the request, move an item out of a restricted collection, and then view or download content the user was not permitted to access. This issue is fixed in versions 2.6.25 and 3.0.8.

CWE CWE-639 CWE-863
Vendor sulu
Product sulu
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for sulu sulu

Be the first to know when new unknown vulnerabilities affecting sulu sulu are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

sulu / sulu
< 2.6.25 >= 3.0.0-alpha1, < 3.0.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sulu/sulu/security/advisories/GHSA-h6cx-gjxx-v25c github.com: https://github.com/sulu/sulu/commit/2b959de75d61b98433e42db462c246ed9e4ce793 github.com: https://github.com/sulu/sulu/releases/tag/2.6.25 github.com: https://github.com/sulu/sulu/releases/tag/3.0.8