CVE-2026-34372

LOW

Sulu checks fix permissions for subentities endpoints

Title source: cna
STIX 2.1

Description

Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even have permission for contacts. This issue has been patched in versions 2.6.22 and 3.0.5.

Scores

CVSS v3 2.7
EPSS 0.0003
EPSS Percentile 9.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-288
Status published
Products (4)
sulu/sulu 1.0.0 - 2.6.22Packagist
sulu/sulu 1.0.0 - 2.6.22
sulu/sulu >= 1.0.0, < 2.6.22
sulu/sulu >= 3.0.0, < 3.0.5
Published Mar 31, 2026
Tracked Since Apr 01, 2026