Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘
🐘 Packagist
Not in CISA KEV
HIGH severity

CVE-2021-43835 — sulu

HIGHFix: sulu/sulu@30bf8b5

CVE-2021-43835 is a high-severity (CVSS 7.2) Improper Privilege Management vulnerability in sulu/sulu. A fix is available for sulu/sulu — see the affected versions and patch details below.

Privilege escalation in the Sulu Admin panel

Also known asGHSA-84px-q68r-2fc9
Published
Updated
Affected
3 pkgs
Patched
3 / 3
Exploits
None indexed
Exploitation data as of Oct 10, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
1.2%probability of exploitation in next 30 days
Lower Risk+0.04%
Lower risk than most CVEs67th percentile — riskier than 67% of all scored CVEsHighest risk
0.00%0.56%1.11%1.67%0.3%1.2%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2021-43835 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

3 pkgs affected
🐘sulu/sulu🐘sulu/sulu🐘sulu/sulu

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

Impact

Impacted are only users which already have access to the admin UI. Over the API it was possible for them to give themselves permissions to areas which they did not already had. This issue was introduced in 2.0.0-RC1 with the new ProfileController putAction.

Patches

The versions have been patched in 2.2.18, 2.3.8 and 2.4.0.

Workarounds

Patching the ProfileController of affected sulu versions yourself by overwriting it.

References

Are there any links users can visit to find out more?

Currently not.

For more information

If you have any questions or comments about this advisory:

Affected Packages

3 total 3 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistsulu/sulu≥ 2.0.0&&< 2.2.182.2.18composer require sulu/sulu:^2.2.18
🐘Packagistsulu/sulu≥ 2.3.0&&< 2.3.82.3.8composer require sulu/sulu:^2.3.8
🐘Packagistsulu/sulu≥ 2.4.0-RC1&&< 2.4.02.4.0composer require sulu/sulu:^2.4.0

Affected Products

1 product · 3 configurations
Application
sulusulu
≥ 2.3.0 && < 2.3.8
1 version
2.4.0

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for sulu/sulu, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update sulu/sulu to 2.2.18 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2021-43835 is resolved across your whole dependency graph.

  3. Workarounds

    Close the privilege gap rather than the entry point: audit which accounts, roles and service identities can reach the affected operation, drop the component to the least privilege it actually needs, and review file and directory permissions created by earlier installs — a default left in place is what makes this reachable.

Frequently Asked Questions

### Impact Impacted are only users which already have access to the admin UI. Over the API it was possible for them to give themselves permissions to areas which they did not already had. This issue was introduced in 2.0.0-RC1 with the new ProfileController putAction. ### Patches The versions have been patched in 2.2.18, 2.3.8 and 2.4.0. ### Workarounds Patching the ProfileController of affected sulu versions yourself by overwriting it. ### References _Are there any links users can visit to find out more?_ Currently not. ### For more information If you have any questions or comments
O3 Security · Impact-Aware SCA

Is CVE-2021-43835 in your dependencies?

Find it across Packagist, including transitive dependencies.

CVE-2021-43835: sulu — Fixed in 2.2.18