Vulnerability Description
Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even have permission for contacts. This issue has been patched in versions 2.6.22 and 3.0.5.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sulu | Sulu | >= 1.0.0, < 2.6.22 |
Related Weaknesses (CWE)
References
- https://github.com/sulu/sulu/releases/tag/2.6.22ProductRelease Notes
- https://github.com/sulu/sulu/releases/tag/3.0.5ProductRelease Notes
- https://github.com/sulu/sulu/security/advisories/GHSA-6h7h-m7p5-hjqpVendor Advisory
FAQ
What is CVE-2026-34372?
CVE-2026-34372 is a vulnerability with a CVSS score of 2.7 (LOW). Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via...
How severe is CVE-2026-34372?
CVE-2026-34372 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-34372?
Check the references section above for vendor advisories and patch information. Affected products include: Sulu Sulu.