Junglewise Threat Intelligence

CVE-2026-34372: Sulu CMS authentication bypass in contact sub-entities API

CVE-2026-34372 · Severity: low · CVSS 2.7 · Published 2026-03-31

Executive brief

Sulu is an open-source content management system used to build and manage websites. A security flaw allowed users with basic administrative access to view sensitive contact information they were not authorized to see. This could lead to the unauthorized exposure of contact details stored within the system. The issue has been fixed in the latest software updates.

Technical details

An authentication bypass (CWE-288) exists in Sulu CMS versions 1.0.0 through 2.6.21 and 3.0.0 through 3.0.4. The vulnerability is located in the admin API endpoints responsible for contact sub-entities. While the system requires a user to have at least one administrative role, it fails to properly verify specific permissions for contact data when accessed through these alternate API paths. An authenticated attacker with low-level admin access can exploit this to retrieve contact information. The issue is resolved in versions 2.6.22 and 3.0.5.

Affected products

  • Sulu Sulu 1.0.0 to < 2.6.22, 3.0.0 to < 3.0.5

Timeline

  • 2026-03-27: patched: Versions 2.6.22 and 3.0.5 released
  • 2026-03-31: disclosed: Public advisory published

References

Related threats