CVE-2026-82396: Sulu
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and its administration variant to honor the inline query parameter for scriptable MIME types. The vulnerable stored Content-Type values include text/html, application/xhtml+xml, text/xml, and application/xml. An attacker with media upload permission can store an HTML, XHTML, or XML document and create a link using inline=1, causing the application to return the file on the Sulu origin instead of forcing Content-Disposition attachment. When an authenticated victim opens the link, attacker-controlled JavaScript can execute with the victim's Sulu-origin session and can read data or perform actions as that victim. This issue is fixed in versions 2.6.25 and 3.0.8.
Affected products
- Sulu Sulu: before 2.6.25 (fixed in 2.6.25); from 3.0.0-alpha1, before 3.0.8 (fixed in 3.0.8)
Published 2026-08-31. Last modified 2026-09-08.