Impact
Prior to 2026.1.5, an authenticated user with objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefinition.php validate only the beginning of each value. When a data object of that class containing a Block field is loaded, Block::load in models/DataObject/ClassDefinition/Data/Block.php incorporates the stored class ID into an unquoted object table identifier, allowing the UID to supply SQL syntax. The resulting query can read or modify arbitrary Pimcore database tables, including disclosure of password hashes, illustrating a severe confidentiality and integrity risk. This flaw represents an incomplete validation hardening because earlier work added a start anchor without enforcing the end of the identifier.
Affected Systems
Pimcore versions prior to 2026.1.5 are affected. The issue occurs when objects with a Block field are loaded after a malicious ClassDefinition UID has been stored. The product is Pimcore, and the fix is deployed in release 2026.1.5.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, indicating high severity. EPSS score is <1%, indicating a very low but nonzero exploitation probability, and the flaw has not been listed in CISA's KEV catalog. The attack requires authenticated access with objects permission; once achieved, an attacker can read or modify database contents. The lack of an end anchor in the validation regular expression is the key weakness that permits the injection.
OpenCVE Enrichment
Github GHSA