Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.6 PHP packages GHSA-jg26-q8hg-3pq4 CVE-2026-92692 PKSA-mg6n-7v6r-wbcq

Unauthenticated JCR-SQL2 Injection in Sulu CMS via Smart Content Category Filter

Sulu CMS versions before 2.6.25 and 3.0.8 contain a JCR-SQL2 injection flaw in the Smart Content QueryBuilder, allowing unauthenticated attackers to manipulate category-based queries to infer unpublished content or degrade site availability.

Synthesized by AI from 3 sources · updated 2 hours ago

AI summary

A vulnerability has been disclosed in Sulu, an open-source PHP content management system built on the Symfony framework. The issue, tracked as CVE-2026-92692, affects the Smart Content QueryBuilder component and can be triggered by unauthenticated visitors on public pages that use category-filtered Smart Content blocks. The vendor has released fixed versions.

What happened

A SQL/JCR-SQL2 injection vulnerability was identified in Sulu's Smart Content QueryBuilder, located in src/Sulu/Component/Content/SmartContent/QueryBuilder.php. The component concatenates category identifiers taken from the public 'categories' query parameter directly into a JCR-SQL2 WHERE clause without validating that the values are numeric. On any public-facing page containing a category-filtered Smart Content block, an attacker can manipulate this parameter to alter the resulting query.

Technical cause

The root cause is improper neutralization of special elements used in a query command (CWE-89), specifically a lack of numeric validation on category identifiers before they are concatenated into a JCR-SQL2 query. Because the query is built through string concatenation rather than parameterized input, an attacker-controlled value in the 'categories' parameter can change the structure of the query that is executed against the content repository.

Why it matters

Exploitation does not require authentication and does not require any user interaction, since the vulnerable code path is reachable through a normal public page request. An attacker can use the flaw to infer or enumerate content-repository nodes, including content that has not been published, which may expose information not intended to be public. Separately, submitting malformed or deliberately expensive query fragments can degrade the availability of the affected site. The advisory explicitly states this injection path does not allow modification of repository data.

Who is affected

Any Sulu CMS deployment running an affected release that includes at least one public page with a category-filtered Smart Content block is potentially exposed, since no authentication is required to reach the vulnerable query logic.

Affected versions

The vulnerability affects sulu/sulu releases prior to 2.6.25 in the 2.6 line, and releases from 3.0.0 up to but not including 3.0.8 in the 3.0 line.

Fixes and mitigation

The vendor has fixed this issue in sulu/sulu versions 2.6.25 and 3.0.8. Sites running affected versions should upgrade to one of these fixed releases.

Recommended action

Administrators of Sulu CMS installations should update to version 2.6.25 (for the 2.6 line) or 3.0.8 (for the 3.0 line) as soon as possible. Prioritize this update for any installation that uses category-filtered Smart Content blocks on publicly accessible pages, given the unauthenticated, no-interaction attack path.

PatchBriefing score

4.6 / 10 · Medium

Official CVSS: 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Why this score

The vulnerability carries a CVSS 4.0 base score of 6.9, driven primarily by its network attack vector, low attack complexity, and the fact that it requires no privileges or user interaction. The PatchWire score of 4.6 reflects this base severity plus modest increases for the unauthenticated and no-user-interaction attack conditions. No known exploitation in the wild, no public exploit code, and no EPSS-driven urgency were factored in, and a fix is already available, which keeps the overall score moderate rather than critical. Impact is limited to confidentiality (disclosure of unpublished content) and availability (resource-intensive queries); the advisory confirms no integrity/data-modification impact.

Affected versions

sulu/sulu >= 3.0.0, < 3.0.8
vulnerable
sulu/sulu >=3.0.0,<3.0.8|<2.6.25
vulnerable
≥ 2.6.25
patched
≥ 3.0.8
patched

Reported fixes

The vendor has fixed this issue in sulu/sulu versions 2.6.25 and 3.0.8. Sites running affected versions should upgrade to one of these fixed releases.

How this was built

3 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • Packagist Security Advisories registry
  • NVD (NIST) database
Unified report
Unauthenticated JCR-SQL2 Injection in Sulu CMS via Smart Content Category Filter
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email