Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82394— Sulu: Fix authorization bypass when creating preview links

Quick assessment

Affected
sulu sulu
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Sulu 是一个基于 Symfony 框架构建的开源 PHP 内容管理系统。在版本 2.6.25 和 3.0.8 之前,其预览链接端点(endpoint)及 中的 或 方法未对目标资源强制要求“查看(VIEW)”权限。 因此,任何已认证的后台管理员用户,只要知道目标资源的标识符,就可以为任意页面、文章或片段(snippet)创建或撤销预览链接,即使该内容位于该用户无权查看的 webspace 或 area 中。生成的预览 URL 是公开的,通过不透明令牌(opaque token)解析内容,使得该用户或任何收到链接

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82394

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sulu: Fix authorization bypass when creating preview links
Source: CVE Program / CVE List V5
Vulnerability Description
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforce VIEW permission for the target resource in PreviewLinkManager::generate() or PreviewLinkManager::revoke(). An authenticated administration user who knows a target resource identifier can create or revoke a preview link for any page, article, or snippet, including content in a webspace or area the user cannot view. A generated preview URL is public and resolves content by an opaque token, allowing the user or anyone receiving the link to read restricted content without authentication. This issue is fixed in versions 2.6.25 and 3.0.8.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sulu sulu < 2.6.25 -

II. Public POCs for CVE-2026-82394

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82394

登录查看更多情报信息。

Other References for CVE-2026-82394 (3)

Same Patch Batch · sulu · 2026-08-31 · 3 CVEs total

CVE-2026-82396 5.4 MEDIUM Sulu: Stored XSS via media download inline-disposition override
CVE-2026-82395 5.3 MEDIUM Sulu: Media move/update authorization bypass (IDOR)

IV. Related Vulnerabilities

V. Comments for CVE-2026-82394

No comments yet


Leave a comment