Description
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefinition.php validate only the beginning of each value. When a data object of that class containing a Block field is loaded, Block::load in models/DataObject/ClassDefinition/Data/Block.php incorporates the stored class ID into an unquoted object table identifier, allowing the UID to supply SQL syntax. The resulting query can read or modify arbitrary Pimcore database tables, including disclosure of password hashes, and the flaw represents an incomplete validation hardening because earlier work added a start anchor without enforcing the end of the identifier. This issue is fixed in version 2026.1.5.
Published: 2026-09-14
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection enabling unauthorized data access and potential destruction
Action: Apply Patch
AI Analysis

Impact

Prior to 2026.1.5, an authenticated user with objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefinition.php validate only the beginning of each value. When a data object of that class containing a Block field is loaded, Block::load in models/DataObject/ClassDefinition/Data/Block.php incorporates the stored class ID into an unquoted object table identifier, allowing the UID to supply SQL syntax. The resulting query can read or modify arbitrary Pimcore database tables, including disclosure of password hashes, illustrating a severe confidentiality and integrity risk. This flaw represents an incomplete validation hardening because earlier work added a start anchor without enforcing the end of the identifier.

Affected Systems

Pimcore versions prior to 2026.1.5 are affected. The issue occurs when objects with a Block field are loaded after a malicious ClassDefinition UID has been stored. The product is Pimcore, and the fix is deployed in release 2026.1.5.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.5, indicating high severity. EPSS score is <1%, indicating a very low but nonzero exploitation probability, and the flaw has not been listed in CISA's KEV catalog. The attack requires authenticated access with objects permission; once achieved, an attacker can read or modify database contents. The lack of an end anchor in the validation regular expression is the key weakness that permits the injection.

Generated by OpenCVE AI on September 20, 2026 at 23:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pimcore to version 2026.1.5 or later, which resolves the regex validation flaw and removes the SQL injection vector
  • If immediate upgrade is not possible, restrict the objects permission to trusted administrators only to limit the potential for malicious UID submissions
  • Consider implementing custom validation that enforces a full match against the allowed identifier format, or strip any embedded SQL characters from UID fields before database interaction

Generated by OpenCVE AI on September 20, 2026 at 23:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2mhj-fhvg-v428 Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
History

Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Pimcore
Pimcore pimcore
Vendors & Products Pimcore
Pimcore pimcore

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefinition.php validate only the beginning of each value. When a data object of that class containing a Block field is loaded, Block::load in models/DataObject/ClassDefinition/Data/Block.php incorporates the stored class ID into an unquoted object table identifier, allowing the UID to supply SQL syntax. The resulting query can read or modify arbitrary Pimcore database tables, including disclosure of password hashes, and the flaw represents an incomplete validation hardening because earlier work added a start anchor without enforcing the end of the identifier. This issue is fixed in version 2026.1.5.
Title Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
Weaknesses CWE-20
CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T17:17:58.863Z

Reserved: 2026-06-16T14:33:35.710Z

Link: CVE-2026-55072

cve-icon Vulnrichment

Updated: 2026-09-14T17:17:54.119Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T17:17:47.610

Modified: 2026-09-16T13:42:48.283

Link: CVE-2026-55072

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')