SQL Injection Vulnerability in Pimcore Data Management Platform
CVE-2026-23492

8.8HIGH

Key Information:

Vendor

Pimcore

Status
Vendor
CVE Published:
14 January 2026

What is CVE-2026-23492?

Pimcore, a popular open-source Data and Experience Management Platform, suffers from an incomplete patch for SQL injection vulnerabilities in its Admin Search Find API. Prior to version 12.3.1 and 11.5.14, the initial remedy attempted to mitigate potential SQL injection attacks by filtering out SQL comments and handling syntax errors. However, this approach proved insufficient, allowing authenticated attackers to exploit blind SQL injection techniques. As a result, attackers could potentially access sensitive database information through the admin interface. The vulnerability has been addressed in the aforementioned versions, enhancing the platform's security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

pimcore >= 12.0.0-RC1, < 12.3.1 < 12.0.0-RC1, 12.3.1

pimcore < 11.5.14 < 11.5.14

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.