CVE-2026-82395Medium▾ SunlitSulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 2.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media item's actual source collection, and src/Sulu/Bundle/MediaBundle/Media/Manager/MediaManager.php allows MediaManager::move() to reassign the item without checking that source. An authenticated backend user with edit permission on one collection and knowledge of a target media identifier can name the allowed collection in the request, move an item out of a restricted collection, and then view or download content the user was not permitted to access. This issue is fixed in versions 2.6.25 and 3.0.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
sulu/sulu <= 2.6.24sulu/sulu >= 3.0.0-alpha1, < 3.0.8Patched in:
sulu/sulu 2.6.25sulu/sulu 3.0.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82394MediumSulu is an open-source PHP content management system based on the Symfony framework
CVE-2026-82396Medium· 5.4Sulu is an open-source PHP content management system based on the Symfony framework
CVE-2026-54180High· 7.6backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels
CVE-2026-52743Medium· 4.3GoCD is a continuous deliver server
CVE-2026-14199High· 7.1Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected
CVE-2026-15630Critical· 9.9CVE-2026-15630