SQL Injection Risk in Pimcore by Authenticated Users
CVE-2026-5394
7HIGH
What is CVE-2026-5394?
An authenticated administrative user with the ability to import or save DataObject class definitions in Pimcore can potentially inject harmful composite index metadata, leading to unintended SQL execution on the backend. This vulnerability highlights the importance of strict access controls and input validation to safeguard against malicious exploitation.
Affected Version(s)
pimcore Windows 12.3.3