CVE-2026-92692
### Impact An unauthenticated JCR-SQL2 injection exists in the Smart Content category filter of the 2.x content query builder. Category IDs supplied through the public `?categories=` query parameter are only trimmed and are then concatenated directly into a JCR-SQL2 `WHERE` clause, without the numeric validation that the equivalent tag filter already performs. Any public page that renders a Smart Content element with category filtering enabled evaluates this parameter, so no authentication or special configuration beyond a category-filtered content block is required. An anonymous visitor can therefore: - inject boolean conditions to infer the existence of, and disclose, content nodes they should not see (for example unpublished pages) via blind boolean-based extraction; and - submit malformed query fragments that cause query errors or resource-intensive queries, degrading availability. Because the sink is a JCR-SQL2 query, the impact is limited to reading and enumerating content-repository nodes and to error/denial-of-service conditions; it cannot be used to modify data through this path. ### Patches Fixed in **2.6.25 and 3.0.8**. Category, tag, and audience-target-group IDs are now cast to integers before they are used in the JCR-SQL2 query, so no attacker-controlled characters can reach the query. ### Workarounds If you cannot upgrade immediately: - Apply the fix manually — cast each ID to an integer where it is concatenated into the category (and, defensively, tag and audience-targeting) `WHERE` clause in the content Smart Content query builder. - Alternatively, disable category filtering on publicly reachable Smart Content elements until the patch is applied.
Properties
- ghsa_id
- GHSA-jg26-q8hg-3pq4
- severity
- medium
- summary
- Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)
- cve_id
- CVE-2026-92692
- signal_observed_at
- 2026-09-23T22:45:22+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-23T18:21:22Z
- source_url
- https://github.com/advisories/GHSA-jg26-q8hg-3pq4
- ghsa_updated
- 2026-09-23T18:21:24Z
Related Entities (4)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
Explore deeper with Ninja Signal's threat intelligence graph