Vulnerability Description
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical hash algorithm. This issue has been patched in versions 2.6.23 and 3.0.6.
Related Weaknesses (CWE)
References
- https://github.com/sulu/sulu/releases/tag/2.6.23
- https://github.com/sulu/sulu/releases/tag/3.0.6
- https://github.com/sulu/sulu/security/advisories/GHSA-7fv8-6pp7-6h85
FAQ
What is CVE-2026-45701?
CVE-2026-45701 is a documented vulnerability. Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical hash...
How severe is CVE-2026-45701?
CVSS scoring is not yet available for CVE-2026-45701. Check NVD for updates.
Is there a patch for CVE-2026-45701?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.