{"id":"GHSA-9m6v-8fxc-4r44","aliases":[],"url":"https://o3.security/vulnerability/GHSA-9m6v-8fxc-4r44","summary":"Sulu: Used API Keys may be available via Admin API","details":"### Impact\n\nThe users endpoint controller exposes a project's apiKey field to the logged-in user, provided they have permission for that endpoint. This only has impact if a project itself uses that specific field, Sulu itself does nothing with it and has no authentication per apiKey in its core.\n\n### Patches\n\nA patch is released with Version 2.6.23 and 3.0.5.\n\n### Workarounds\n\nRemove the field descriptor by patch the UserController.php File in Sulu Security Bundle.","published":"2026-05-18T17:34:06Z","modified":"2026-05-18T17:46:18.697711Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"3.0.6"},{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"2.6.23"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/sulu/sulu/security/advisories/GHSA-9m6v-8fxc-4r44"},{"type":"PACKAGE","url":"https://github.com/sulu/sulu"},{"type":"WEB","url":"https://github.com/sulu/sulu/releases/tag/2.6.23"},{"type":"WEB","url":"https://github.com/sulu/sulu/releases/tag/3.0.6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-18T17:46:18.697711Z"}}