mediumVulnerability

CVE-2026-92692

### Impact An unauthenticated JCR-SQL2 injection exists in the Smart Content category filter of the 2.x content query builder. Category IDs supplied through the public `?categories=` query parameter are only trimmed and are then concatenated directly into a JCR-SQL2 `WHERE` clause, without the numeric validation that the equivalent tag filter already performs. Any public page that renders a Smart Content element with category filtering enabled evaluates this parameter, so no authentication or special configuration beyond a category-filtered content block is required. An anonymous visitor can therefore: - inject boolean conditions to infer the existence of, and disclose, content nodes they should not see (for example unpublished pages) via blind boolean-based extraction; and - submit malformed query fragments that cause query errors or resource-intensive queries, degrading availability. Because the sink is a JCR-SQL2 query, the impact is limited to reading and enumerating content-repository nodes and to error/denial-of-service conditions; it cannot be used to modify data through this path. ### Patches Fixed in **2.6.25 and 3.0.8**. Category, tag, and audience-target-group IDs are now cast to integers before they are used in the JCR-SQL2 query, so no attacker-controlled characters can reach the query. ### Workarounds If you cannot upgrade immediately: - Apply the fix manually — cast each ID to an integer where it is concatenated into the category (and, defensively, tag and audience-targeting) `WHERE` clause in the content Smart Content query builder. - Alternatively, disable category filtering on publicly reachable Smart Content elements until the patch is applied.

Properties

ghsa_id
GHSA-jg26-q8hg-3pq4
severity
medium
summary
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)
cve_id
CVE-2026-92692
signal_observed_at
2026-09-23T22:45:22+00:00
is_ghsa_only
false
ghsa_published
2026-09-23T18:21:22Z
source_url
https://github.com/advisories/GHSA-jg26-q8hg-3pq4
ghsa_updated
2026-09-23T18:21:24Z

Related Entities (4)

AFFECTS (1)

[Software]composer/sulu/sulu

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/sulu/sulu

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92692 — Ninja Signal Threat Intelligence | Ninja Signal