SQL Injection Vulnerability in Pimcore Data Management Platform
CVE-2026-23492
What is CVE-2026-23492?
Pimcore, a popular open-source Data and Experience Management Platform, suffers from an incomplete patch for SQL injection vulnerabilities in its Admin Search Find API. Prior to version 12.3.1 and 11.5.14, the initial remedy attempted to mitigate potential SQL injection attacks by filtering out SQL comments and handling syntax errors. However, this approach proved insufficient, allowing authenticated attackers to exploit blind SQL injection techniques. As a result, attackers could potentially access sensitive database information through the admin interface. The vulnerability has been addressed in the aforementioned versions, enhancing the platform's security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
pimcore >= 12.0.0-RC1, < 12.3.1 < 12.0.0-RC1, 12.3.1
pimcore < 11.5.14 < 11.5.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved