Executive brief
Pimcore's Studio API endpoint for creating class definitions incorrectly validates permissions, allowing any content editor with the standard "objects" permission to create new database tables and PHP class files—operations normally restricted to administrators. This privilege escalation lets unprivileged users modify the application schema, introduce structural data model changes, and trigger server-side operations outside their permission scope.
Technical details
Two permission and validation issues exist in `pimcore/studio-backend-bundle`. First, the endpoint `POST /pimcore-studio/api/class/definition/configuration-view/detail/create` is protected by the `DATA_OBJECTS` permission (guarding data object editing) rather than the `CLASSES` permission (required for class definition management in Classic Admin). Any authenticated user with object-editing rights can exploit this to create class definitions, bypassing admin-only restrictions. Second, the `CreateClassDefinitionParameters` class performs only an empty-string check on the `uid` field; it lacks the anchored regex validation (`/^[a-zA-Z0-9][a-zA-Z0-9_]*$/`) that exists in the model layer, allowing malformed UIDs to reach the model layer and trigger unhandled internal exceptions that expose stack traces in debug configurations. Authentication is required (valid Pimcore session with `objects` permission), and no victim interaction is needed. The vulnerability is fixed in versions 2025.4.6 and 2026.1.6.
Affected products
- Pimcore studio-backend-bundle < 2025.4.6, >= 2026.1.0 < 2026.1.6
Timeline
- 2026-08-28: disclosed: Published to GitHub Advisory Database
- 2026-06-29: patched: Fix released in versions 2025.4.6 and 2026.1.6