Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. sulu/sulu
  4. ›
  5. CVE-2026-34372

CVE-2026-34372: Sulu checks fix permissions for subentities endpoints

March 30, 2026

A user which has permission for the Sulu Admin via atleast one role could have access to the subentities of contacts via the admin API without even have permission for contacts.

References

  • github.com/advisories/GHSA-6h7h-m7p5-hjqp
  • github.com/sulu/sulu
  • github.com/sulu/sulu/releases/tag/2.6.22
  • github.com/sulu/sulu/releases/tag/3.0.5
  • github.com/sulu/sulu/security/advisories/GHSA-6h7h-m7p5-hjqp
  • nvd.nist.gov/vuln/detail/CVE-2026-34372

Code Behaviors & Features

Detect and mitigate CVE-2026-34372 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.0.0 before 2.6.22, all versions starting from 3.0.0 before 3.0.5

Fixed versions

  • 2.6.22
  • 3.0.5

Solution

Upgrade to versions 2.6.22, 3.0.5 or above.

Weakness

  • CWE-288: Authentication Bypass Using an Alternate Path or Channel

Source file

packagist/sulu/sulu/CVE-2026-34372.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 31 Mar 2026 12:19:53 +0000.