SQL Injection Vulnerability in Pimcore Data Management Platform
CVE-2026-23492
8.8HIGH
What is CVE-2026-23492?
Pimcore, a popular open-source Data and Experience Management Platform, suffers from an incomplete patch for SQL injection vulnerabilities in its Admin Search Find API. Prior to version 12.3.1 and 11.5.14, the initial remedy attempted to mitigate potential SQL injection attacks by filtering out SQL comments and handling syntax errors. However, this approach proved insufficient, allowing authenticated attackers to exploit blind SQL injection techniques. As a result, attackers could potentially access sensitive database information through the admin interface. The vulnerability has been addressed in the aforementioned versions, enhancing the platform's security.
Affected Version(s)
pimcore >= 12.0.0-RC1, < 12.3.1 < 12.0.0-RC1, 12.3.1
pimcore < 11.5.14 < 11.5.14