THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-65cv-w493-7vhq (medium) — Sulu: Fix authorization bypass when creating preview links

[GHSA] GHSA-65cv-w493-7vhq (medium) — Sulu: Fix authorization bypass when creating preview links

medgithub_advisoriesPublished 2026-09-02

GHSA-65cv-w493-7vhq Severity: medium CVE: CVE-2026-82394

Sulu: Fix authorization bypass when creating preview links

### Impact

A missing authorization check on the preview link endpoint lets a backend user create a public, unauthenticated preview URL for content they are not allowed to see.

`PreviewLinkController` (and the underlying `PreviewLinkManager::generate()` / `revoke()`) never enforce

Indicators of compromise

Original source: https://github.com/advisories/GHSA-65cv-w493-7vhq