CVE-2026-82395 | Sulu up to 2.6.24/3.0.7 Media Move Endpoint MediaManager.php MediaManager::move collection permission
A vulnerability classified as problematic was found in Sulu up to 2.6.24/3.0.7. This vulnerability affects the function MediaManager::move of the file src/Sulu/Bundle/MediaBundle/Media/Manager/MediaManager.php of the component Media Move Endpoint. The manipulation of the argument collection results in permission issues.
This vulnerability was named CVE-2026-82395. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More