Description
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php and bundles/CustomReportsBundle/src/Tool/Config/Listing/Dao.php, allowing a low-privileged backend user with the reports permission to directly request an unshared report such as poc-secret-report by name and read report name, grouping information, display and icon metadata, data source configuration, column configuration, and sharing settings even when shareGlobally is false. This issue is fixed in versions 11.5.17 (LTS) and 12.3.6.
Published: 2026-07-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Pimcore’s CustomReports module contains an authorization inconsistency between the report listing endpoint and the report detail endpoint. This flaw allows a backend user who has only the generic reports permission to request a report that has not been shared, such as "poc-secret-report", and receive its full metadata, including name, grouping information, display and icon data, data source configuration, column configuration, and sharing settings even when the report’s shareGlobally flag is false. The vulnerability results in the confidential disclosure of report configuration data but does not enable code execution, data modification, or other destructive actions.

Affected Systems

The issue affects installations of Pimcore that include the CustomReportsBundle component. Any site running a Pimcore version prior to 11.5.17 on the LTS line or prior to 12.3.6 on the current release line is vulnerable. Versions 11.5.17 (LTS) and 12.3.6 and later contain the fix and are not affected.

Risk and Exploitability

The CVSS score of 7.1 classifies this as high severity. The EPSS score of less than 1% indicates that, at present, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated backend user with the reports permission, which could be an insider or an attacker who has compromised such an account. The attacker can trigger the bypass by sending a request to the report detail endpoint with a valid report name, thereby retrieving metadata that should remain private. This is an authenticated access flaw; it does not require additional system compromise or remote code execution.

Generated by OpenCVE AI on August 1, 2026 at 08:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pimcore to version 11.5.17 LTS, 12.3.6, or newer to apply the authorization fix
  • Restrict the reports permission to a minimal set of trusted administrators to reduce the attack surface
  • If an immediate upgrade is not possible, disable or restrict the CustomReportsBundle to prevent unauthorized access

Generated by OpenCVE AI on August 1, 2026 at 08:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jwcc-gv4m-93x6 Pimcore has a CustomReports Share Bypass
History

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Pimcore
Pimcore pimcore
Vendors & Products Pimcore
Pimcore pimcore

Fri, 17 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Description Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php and bundles/CustomReportsBundle/src/Tool/Config/Listing/Dao.php, allowing a low-privileged backend user with the reports permission to directly request an unshared report such as poc-secret-report by name and read report name, grouping information, display and icon metadata, data source configuration, column configuration, and sharing settings even when shareGlobally is false. This issue is fixed in versions 11.5.17 (LTS) and 12.3.6.
Title Pimcore: CustomReports Share Bypass
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-20T13:53:55.744Z

Reserved: 2026-05-13T04:38:01.165Z

Link: CVE-2026-45704

cve-icon Vulnrichment

Updated: 2026-07-20T13:53:34.893Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:30:03Z

Weaknesses