CVE-2026-82395: Sulu

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media item's actual source collection, and src/Sulu/Bundle/MediaBundle/Media/Manager/MediaManager.php allows MediaManager::move() to reassign the item without checking that source. An authenticated backend user with edit permission on one collection and knowledge of a target media identifier can name the allowed collection in the request, move an item out of a restricted collection, and then view or download content the user was not permitted to access. This issue is fixed in versions 2.6.25 and 3.0.8.

Affected products

  • Sulu Sulu: before 2.6.25 (fixed in 2.6.25); from 3.0.0-alpha1, before 3.0.8 (fixed in 3.0.8)

Published 2026-08-31. Last modified 2026-09-08.