Executive brief
A security flaw in the Symfony web framework allows unauthorized users to bypass security firewalls and access protected administrative pages or data. By sending a specially crafted login request that intentionally fails, an attacker can trick the system into displaying internal pages that should require a password. This could lead to the exposure of sensitive information, such as internal reports, user data, or administrative dashboards, even if the application is otherwise correctly configured.
Technical details
An authorization bypass exists in Symfony's DefaultAuthenticationFailureHandler when the 'failure_forward' configuration is set to true. The handler incorrectly honors the '_failure_path' parameter provided in a login request, using it to dispatch an internal subrequest via HttpKernelInterface::SUB_REQUEST. Because Symfony's Firewall listener is designed to skip subrequests, the AccessListener (which enforces access_control rules) is bypassed. An unauthenticated attacker can exploit this by submitting a failing login request with a malicious '_failure_path' to access any GET route protected by the firewall. The issue is resolved in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13 by ensuring the handler only uses the developer-configured failure path.
Affected products
- Symfony symfony/symfony < 5.4.53, >= 6.0.0-BETA1 < 6.4.41, >= 7.0.0-BETA1 < 7.4.13, >= 8.0.0-BETA1 < 8.0.13
- Symfony symfony/security-http < 5.4.53, >= 6.0.0-BETA1 < 6.4.41, >= 7.0.0-BETA1 < 7.4.13, >= 8.0.0-BETA1 < 8.0.13
Timeline
- 2026-05-27: patched: Security releases v5.4.53, v6.4.41, v7.4.13, and v8.0.13 published.
- 2026-07-14: disclosed: CVE-2026-48489 published.
References
- https://github.com/symfony/symfony/commit/c48a4276309e11aedeeb0ce3a89dfbf0b4fe04ff
- https://github.com/symfony/symfony/releases/tag/v5.4.53
- https://github.com/symfony/symfony/releases/tag/v6.4.41
- https://github.com/symfony/symfony/releases/tag/v7.4.13
- https://github.com/symfony/symfony/security/advisories/GHSA-6h46-9jf5-q59x