SQL Injection Risk in Pimcore by Authenticated Users
CVE-2026-5394

7HIGH

Key Information:

Vendor

Pimcore

Status
Vendor
CVE Published:
27 April 2026

What is CVE-2026-5394?

An authenticated administrative user with the ability to import or save DataObject class definitions in Pimcore can potentially inject harmful composite index metadata, leading to unintended SQL execution on the backend. This vulnerability highlights the importance of strict access controls and input validation to safeguard against malicious exploitation.

Affected Version(s)

pimcore Windows 12.3.3

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Oscar Naveda
Fluid Attacks' AI SAST Scanner
.