Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82395— Sulu: Media move/update authorization bypass (IDOR)

Quick assessment

Affected
sulu sulu
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Sulu 是一个基于 Symfony 框架的开源 PHP 内容管理系统。在 2.6.25 和 3.0.8 版本之前,媒体移动接口的权限检查是从客户端提供的集合值中派生的,而不是从媒体项的实际源集合中获取;此外, 中的 方法允许在不检查源集合的情况下重新分配媒体项。因此,拥有某个集合编辑权限并知晓目标媒体标识符的已认证后端用户,可以在请求中指定一个允许的集合,从而将媒体项从一个受限集合中移动出去,进而查看或下载用户原本无权访问的内容。该问题已在 2.6.25 和 3.0.8 版本中修复。

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82395

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sulu: Media move/update authorization bypass (IDOR)
Source: CVE Program / CVE List V5
Vulnerability Description
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media item's actual source collection, and src/Sulu/Bundle/MediaBundle/Media/Manager/MediaManager.php allows MediaManager::move() to reassign the item without checking that source. An authenticated backend user with edit permission on one collection and knowledge of a target media identifier can name the allowed collection in the request, move an item out of a restricted collection, and then view or download content the user was not permitted to access. This issue is fixed in versions 2.6.25 and 3.0.8.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sulu sulu < 2.6.25 -

II. Public POCs for CVE-2026-82395

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82395

登录查看更多情报信息。

Other References for CVE-2026-82395 (4)

Same Patch Batch · sulu · 2026-08-31 · 3 CVEs total

CVE-2026-82396 5.4 MEDIUM Sulu: Stored XSS via media download inline-disposition override
CVE-2026-82394 5.3 MEDIUM Sulu: Fix authorization bypass when creating preview links

IV. Related Vulnerabilities

V. Comments for CVE-2026-82395

No comments yet


Leave a comment