CVE-2026-82394

Source
https://cve.org/CVERecord?id=CVE-2026-82394
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82394.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82394
Aliases
Published
2026-08-31T21:17:49Z
Modified
2026-09-10T03:31:01Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Sulu: Fix authorization bypass when creating preview links
Details

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforce VIEW permission for the target resource in PreviewLinkManager::generate() or PreviewLinkManager::revoke(). An authenticated administration user who knows a target resource identifier can create or revoke a preview link for any page, article, or snippet, including content in a webspace or area the user cannot view. A generated preview URL is public and resolves content by an opaque token, allowing the user or anyone receiving the link to read restricted content without authentication. This issue is fixed in versions 2.6.25 and 3.0.8.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-862",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82394.json"
}
References

Affected packages

Git / github.com/sulu/sulu

Affected ranges

Type
GIT
Repo
https://github.com/sulu/sulu
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.6.25"
        },
        {
            "introduced": "3.0.0-alpha1"
        },
        {
            "fixed": "3.0.8"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.2.0
0.4.0
0.5.0
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.8
0.7.0
0.7.1
0.8.0
0.8.3
0.8.4
0.8.5
1.*
1.4.0-RC1
1.4.0-RC2
1.5.0-RC1
1.5.0-RC2
1.5.0-RC3
1.6.0-RC1
2.*
2.0.0
2.0.0-RC1
2.0.0-RC2
2.0.0-RC3
2.0.0-alpha1
2.0.0-alpha2
2.0.0-alpha3
2.0.0-alpha4
2.0.0-alpha5
2.0.0-alpha6
2.1.0-RC1
2.2.0
2.2.0-RC1
2.2.1
2.3.0
2.3.0-RC1
2.3.0-RC2
2.3.1
2.4.0
2.4.0-RC1
2.5.0
2.5.0-alpha1
2.5.1
2.6.0
2.6.0-RC1
2.6.0-RC2
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
3.*
3.0.0
3.0.0-RC1
3.0.0-RC2
3.0.0-alpha1
3.0.0-alpha3
3.0.0-alpha4
3.0.0-alpha5
3.0.0-beta1
3.0.0-beta2
3.0.0-beta3
3.0.0-beta4
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82394.json"