THREAT OPS › Threat News › [GHSA] GHSA-65cv-w493-7vhq (medium) — Sulu: Fix authorization bypass when creating preview links
[GHSA] GHSA-65cv-w493-7vhq (medium) — Sulu: Fix authorization bypass when creating preview links
GHSA-65cv-w493-7vhq Severity: medium CVE: CVE-2026-82394
Sulu: Fix authorization bypass when creating preview links
### Impact
A missing authorization check on the preview link endpoint lets a backend user create a public, unauthenticated preview URL for content they are not allowed to see.
`PreviewLinkController` (and the underlying `PreviewLinkManager::generate()` / `revoke()`) never enforce
Indicators of compromise
- CVE-2026-82394cve
Original source: https://github.com/advisories/GHSA-65cv-w493-7vhq