{"id":"CVE-2026-92692","published":"2026-09-23T19:19:44.103","lastModified":"2026-09-23T20:17:22.020","description":"Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/QueryBuilder.php that concatenates category identifiers from the public categories query parameter into a JCR-SQL2 WHERE clause without numeric validation. On a public page containing a category-filtered Smart Content block, an unauthenticated attacker can alter query conditions to infer or enumerate content-repository nodes, including unpublished content, or submit malformed and expensive query fragments that degrade availability; this path does not modify repository data. This issue is fixed in versions 2.6.25 and 3.0.8.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://github.com/sulu/sulu/commit/d19c01487af8c3de2fb3aa145856707a6367392c","tags":[]},{"url":"https://github.com/sulu/sulu/releases/tag/2.6.25","tags":[]},{"url":"https://github.com/sulu/sulu/releases/tag/3.0.8","tags":[]},{"url":"https://github.com/sulu/sulu/security/advisories/GHSA-jg26-q8hg-3pq4","tags":[]}],"exploitRefs":[{"url":"https://github.com/sulu/sulu/commit/d19c01487af8c3de2fb3aa145856707a6367392c","tags":[]},{"url":"https://github.com/sulu/sulu/releases/tag/2.6.25","tags":[]},{"url":"https://github.com/sulu/sulu/releases/tag/3.0.8","tags":[]},{"url":"https://github.com/sulu/sulu/security/advisories/GHSA-jg26-q8hg-3pq4","tags":[]}],"hasPoc":true,"ai":null}