HomePimcoreCVE-2026-23492

CVE-2026-23492

HIGH
8.8CVSS
Published: 2026-01-14
Updated: 2026-01-20
AI Analysis

Description

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, an incomplete SQL injection patch in the Admin Search Find API allows an authenticated attacker to perform blind SQL injection. Although CVE-2023-30848 attempted to mitigate SQL injection by removing SQL comments (--) and catching syntax errors, the fix is insufficient. Attackers can still inject SQL payloads that do not rely on comments and infer database information via blind techniques. This vulnerability affects the admin interface and can lead to database information disclosure. This vulnerability is fixed in 12.3.1 and 11.5.14.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-89

Metadata

Primary Vendor
PIMCORE
Published
1/14/2026
Last Modified
1/20/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

pimcore : pimcorepimcore : pimcore

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2026-23492 | HIGH Severity | CVEDatabase.com | CVEDatabase.com