CVE Database
/

CVE-2026-34372

Back to search

CVE-2026-34372

Published: Mar 31, 2026

Modified: Mar 31, 2026

PUBLISHED

Description

Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even have permission for contacts. This issue has been patched in versions 2.6.22 and 3.0.5.

VendorProductVersions

sulu

sulu

affected
>= 1.0.0, < 2.6.22
affected
>= 3.0.0, < 3.0.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now