Medium · 4.6 PHP packages GHSA-jg26-q8hg-3pq4 CVE-2026-92692 PKSA-mg6n-7v6r-wbcq
Unauthenticated JCR-SQL2 Injection in Sulu CMS via Smart Content Category Filter
Sulu CMS versions before 2.6.25 and 3.0.8 contain a JCR-SQL2 injection flaw in the Smart Content QueryBuilder, allowing unauthenticated attackers to manipulate category-based queries to infer unpublished content or degrade site availability.
AI summary
A vulnerability has been disclosed in Sulu, an open-source PHP content management system built on the Symfony framework. The issue, tracked as CVE-2026-92692, affects the Smart Content QueryBuilder component and can be triggered by unauthenticated visitors on public pages that use category-filtered Smart Content blocks. The vendor has released fixed versions.
What happened
A SQL/JCR-SQL2 injection vulnerability was identified in Sulu's Smart Content QueryBuilder, located in src/Sulu/Component/Content/SmartContent/QueryBuilder.php. The component concatenates category identifiers taken from the public 'categories' query parameter directly into a JCR-SQL2 WHERE clause without validating that the values are numeric. On any public-facing page containing a category-filtered Smart Content block, an attacker can manipulate this parameter to alter the resulting query.
Technical cause
The root cause is improper neutralization of special elements used in a query command (CWE-89), specifically a lack of numeric validation on category identifiers before they are concatenated into a JCR-SQL2 query. Because the query is built through string concatenation rather than parameterized input, an attacker-controlled value in the 'categories' parameter can change the structure of the query that is executed against the content repository.
Why it matters
Exploitation does not require authentication and does not require any user interaction, since the vulnerable code path is reachable through a normal public page request. An attacker can use the flaw to infer or enumerate content-repository nodes, including content that has not been published, which may expose information not intended to be public. Separately, submitting malformed or deliberately expensive query fragments can degrade the availability of the affected site. The advisory explicitly states this injection path does not allow modification of repository data.
Who is affected
Any Sulu CMS deployment running an affected release that includes at least one public page with a category-filtered Smart Content block is potentially exposed, since no authentication is required to reach the vulnerable query logic.
Affected versions
The vulnerability affects sulu/sulu releases prior to 2.6.25 in the 2.6 line, and releases from 3.0.0 up to but not including 3.0.8 in the 3.0 line.
Fixes and mitigation
The vendor has fixed this issue in sulu/sulu versions 2.6.25 and 3.0.8. Sites running affected versions should upgrade to one of these fixed releases.
Recommended action
Administrators of Sulu CMS installations should update to version 2.6.25 (for the 2.6 line) or 3.0.8 (for the 3.0 line) as soon as possible. Prioritize this update for any installation that uses category-filtered Smart Content blocks on publicly accessible pages, given the unauthenticated, no-interaction attack path.
PatchBriefing score
4.6 / 10 · Medium
Official CVSS: 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
The vulnerability carries a CVSS 4.0 base score of 6.9, driven primarily by its network attack vector, low attack complexity, and the fact that it requires no privileges or user interaction. The PatchWire score of 4.6 reflects this base severity plus modest increases for the unauthenticated and no-user-interaction attack conditions. No known exploitation in the wild, no public exploit code, and no EPSS-driven urgency were factored in, and a fix is already available, which keeps the overall score moderate rather than critical. Impact is limited to confidentiality (disclosure of unpublished content) and availability (resource-intensive queries); the advisory confirms no integrity/data-modification impact.
Affected versions
- sulu/sulu >= 3.0.0, < 3.0.8
- vulnerable
- sulu/sulu >=3.0.0,<3.0.8|<2.6.25
- vulnerable
- ≥ 2.6.25
- patched
- ≥ 3.0.8
- patched
Reported fixes
The vendor has fixed this issue in sulu/sulu versions 2.6.25 and 3.0.8. Sites running affected versions should upgrade to one of these fixed releases.
How this was built
3 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
Packagist Security Advisories registry
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email