Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6h7h-m7p5-hjqp | Sulu checks fix permissions for subentities endpoints |
Fri, 10 Apr 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sulu:sulu:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sulu
Sulu sulu |
|
| Vendors & Products |
Sulu
Sulu sulu |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even have permission for contacts. This issue has been patched in versions 2.6.22 and 3.0.5. | |
| Title | Sulu checks fix permissions for subentities endpoints | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-31T20:29:14.584Z
Reserved: 2026-03-27T13:43:14.369Z
Link: CVE-2026-34372
Updated: 2026-03-31T20:29:09.677Z
Status : Analyzed
Published: 2026-03-31T21:16:29.840
Modified: 2026-04-10T01:40:29.000
Link: CVE-2026-34372
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:45:55Z
Github GHSA