Improper access control in Sulu - CVE-2024-27915
Published: March 4, 2024 / Updated: May 12, 2026
Sulu
Detailed vulnerability description
The vulnerability allows a remote user to bypass page access restrictions.
The vulnerability exists due to improper access control in page access control for secured webspaces when handling page access requests. A remote user can access pages regardless of configured role permissions to bypass page access restrictions.
Only webspaces with a security system configured and permission checks enabled are affected.