Junglewise Threat Intelligence

Pimcore SQL injection in DataObject composite index handling

Severity: high · CVSS 7 · Published 2026-04-27

Technologies: Pimcore, pimcore/pimcore (Packagist). Vendors: Pimcore, Packagist.

Executive brief

Pimcore is an open-source platform used for managing digital data and customer experiences. A security vulnerability allows administrative users to execute unauthorized database commands by manipulating data object settings. This could lead to the exposure of sensitive information or unauthorized changes to the system's database.

Technical details

An SQL injection vulnerability exists in Pimcore version 12.3.3 within the handling of DataObject composite index metadata. Authenticated administrative users with permissions to import or save DataObject class definitions can inject attacker-controlled metadata, leading to unintended SQL execution in the backend database. The vulnerability is classified as CWE-89 (SQL Injection). Exploitation requires high privileges (PR:H) but can be performed over the network without user interaction. A fix has been proposed in Pimcore pull request #19108.

Affected products

  • Pimcore Pimcore 12.3.3

Timeline

  • 2026-04-27: disclosed: Vulnerability disclosed by Fluid Attacks and published to NVD/GHSA.
  • 2026-05-28: other: Advisory GHSA-c8g3-x47w-8q7p withdrawn as a duplicate of GHSA-r2f4-ff2p-xc64.

References

Related threats