CVE-2026-34372 | Sulu up to 2.6.21/3.0.4 Admin API authentication bypass (GHSA-6h7h-m7p5-hjqp)
A vulnerability was found in Sulu up to 2.6.21/3.0.4. It has been rated as critical. This issue affects some unknown processing of the component Admin API. Performing a manipulation results in authentication bypass using alternate channel.
This vulnerability is identified as CVE-2026-34372. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.