A user which has permission for the Sulu Admin via atleast one role could have access to the subentities of contacts via the admin API without even have permission for contacts.
The issue was patched in release 2.6.22 and 3.0.5.
Create a Symfony Request Listener checking the permissions for the specific roles.
Github Advisory: https://github.com/sulu/sulu/security/advisories/GHSA-6h7h-m7p5-hjqp
{
"cwe_ids": [
"CWE-288"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-30T18:04:10Z",
"nvd_published_at": "2026-03-31T21:16:29Z",
"severity": "MODERATE"
}