Junglewise Threat Intelligence

CVE-2026-55208: Pimcore Studio Backend Bundle SQL injection in DateFilter

CVE-2026-55208 · Severity: high · CVSS 7.7 · Published 2026-07-09

Technologies: Pimcore Studio Backend Bundle, Pimcore. Vendors: Pimcore.

Executive brief

Pimcore, a popular open-source PIM and CMS platform, contains a SQL injection vulnerability in its listing filter API that allows authenticated users to extract sensitive database contents including admin password hashes. An attacker with access to listing endpoints can bypass insufficient input validation by injecting SQL metacharacters into column filter parameters, enabling time-based data exfiltration. This compromises confidentiality of all database records and enables account takeover via password recovery tokens.

Technical details

The vulnerability exists in `src/Listing/Filter/DateFilter.php` and `src/Note/Service/FilterService.php`, where user-supplied column names from the `columnFilters[].key` parameter are concatenated directly into SQL BETWEEN clauses using only simple backtick wrapping: `` '`' . $key . '`' ``. Unlike the safe `quoteIdentifier()` method used elsewhere in the codebase (which doubles internal backticks), manual wrapping does not escape embedded backtick characters. An attacker can inject a backtick followed by SQL injection payload (e.g., `id` BETWEEN 0 AND 99999999999) AND SLEEP(3)-- `) to break out of the identifier quoting and inject arbitrary SQL. The attack is enabled because DateFilter uses fixed, hardcoded parameter names (`:minTime`, `:maxTime`) rather than the column name itself as the parameter, bypassing PDO validation. Precondition: the attacker must be authenticated and have access to at least one listing endpoint supporting DateFilter on clause (12+ endpoints affected). Impact: full database read access via time-based blind SQLi, extractable data includes user password hashes, password recovery tokens, and all PIM/CMS content. Patches available in versions 2025.4.6 and 2026.1.6+.

Affected products

  • Pimcore Pimcore < 2025.4.6, >= 2026.1.0 and < 2026.1.6
  • Pimcore studio-backend-bundle < 2025.4.6, >= 2026.1.0 and < 2026.1.6

Timeline

  • 2026-06-29: disclosed: GitHub Advisory published
  • 2026-08-28: advisory: Advisory updated with additional details
  • 2026-06-29: patched: Patches released in versions 2025.4.6 and 2026.1.6

References

Related threats