CVE-2026-34372: Sulu checks fix permissions for subentities endpoints
Impact
A user which has permission for the Sulu Admin via atleast one role could have access to the subentities of contacts via the admin API without even have permission for contacts.
Patches
The issue was patched in release 2.6.22 and 3.0.5.
Workarounds
Create a Symfony Request Listener checking the permissions for the specific roles.
Resources
Github Advisory: https://github.com/sulu/sulu/security/advisories/GHSA-6h7h-m7p5-hjqp
Other sources
Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even have permission for contacts. This issue has been patched in versions 2.6.22 and 3.0.5.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/sulu/suluto a version that resolves this vulnerability.Fixed in 3.0.5 - Upgrade
Upgrade
composer/sulu/suluto a version that resolves this vulnerability.Fixed in 2.6.22 - Upgrade
Upgrade
sulu/suluto a version that resolves this vulnerability.Fixed in 2.6.22 - Upgrade
Upgrade
sulu/suluto a version that resolves this vulnerability.Fixed in 3.0.5