Use of a broken or risky cryptographic algorithm in Sulu - CVE-2026-45701
Published: May 12, 2026
Vulnerability details
The vulnerability allows a remote user to compromise the security of generated api keys and password reset tokens.
The vulnerability exists due to use of a broken or risky cryptographic algorithm in API key generation and password reset token generation when generating security tokens. A remote user can obtain or predict weakly generated values to compromise the security of generated api keys and password reset tokens.