CVE-2026-82396: Sulu: Stored XSS via media download inline-disposition override

Published Aug 31, 2026
·
Updated

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and its administration variant to honor the inline query parameter for scriptable MIME types. The vulnerable stored Content-Type values include text/html, application/xhtml+xml, text/xml, and application/xml. An attacker with media upload permission can store an HTML, XHTML, or XML document and create a link using inline=1, causing the application to return the file on the Sulu origin instead of forcing Content-Disposition attachment. When an authenticated victim opens the link, attacker-controlled JavaScript can execute with the victim's Sulu-origin session and can read data or perform actions as that victim. This issue is fixed in versions 2.6.25 and 3.0.8.

Affected Software

2 affected components
Sulu Sulu<2.6.25
Sulu Sulu<3.0.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade sulu to a version that resolves this vulnerability.

    Fixed in 2.6.25
  2. Upgrade

    Upgrade sulu to a version that resolves this vulnerability.

    Fixed in 3.0.8

Event History

Aug 31, 2026
CVE Published
via MITRE·09:23 PM
Data Sourced
via MITRE·09:23 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs permission to upload media in Sulu. They can upload an HTML, XHTML, or XML document with a scriptable Content-Type and send a crafted media download link containing inline=1 to an authenticated victim.

2

Which deployments are affected?

Sulu versions before 2.6.25 and 3.0.8 are affected. The exposed endpoints are the /media/{id}/download/{slug} route and its administration variant when they honor inline=1 for text/html, application/xhtml+xml, text/xml, or application/xml content.

3

What is the impact if a victim opens a malicious link?

The uploaded document is served inline on the Sulu origin rather than as a forced download. Its JavaScript can run using the victim's Sulu-origin session, allowing it to read data or perform actions available to that victim.

4

What should be done to remediate the issue?

Upgrade to Sulu 2.6.25 or 3.0.8. If an immediate upgrade is not possible, do not allow untrusted users to retain media upload permission and avoid opening media download links with inline=1 for HTML, XHTML, or XML uploads.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203