PT-2026-2947 · Pimcore · Pimcore

Snow1Nd

·

Published

2026-01-14

·

Updated

2026-01-20

·

CVE-2026-23492

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pimcore versions prior to 12.3.1 Pimcore versions prior to 11.5.14
Description Pimcore is an Open Source Data & Experience Management Platform. An incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. The initial patch attempted to mitigate SQL injection by removing SQL comments and catching syntax errors, but this fix was insufficient as attackers can still inject SQL payloads that do not rely on comments and infer database information via blind techniques. This affects the admin interface and can lead to database information disclosure. The vulnerable API endpoint is /admin/search/find. The vulnerability is exploitable through crafted SQL payloads submitted to the API.
Recommendations Update Pimcore to version 12.3.1 or later. Update Pimcore to version 11.5.14 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23492
GHSA-QVR7-7G55-69XJ

Affected Products

Pimcore