Impact
An authenticated user with reports_config permission can enter malicious SQL fragments into the sql, from, where, and groupby fields of a Custom Reports configuration in Pimcore. The buildQueryString() method combines these values directly into a SQL statement, relying on a blacklist that only removes a few hazardous constructs, while the getData() method incorrectly inserts offset and limit values into a LIMIT clause without type casting. Running such a report causes the crafted query to be executed through fetchAllAssociative(), allowing the attacker to disclose, modify, or delete arbitrary database data. The vulnerability affects all Pimcore versions prior to 11.5.19, 12.3.10, and 2026.1.6 and is resolved in those releases.
Affected Systems
Pimcore versions prior to 11.5.19, 12.3.10, and 2026.1.6 are affected. The vulnerability resides in the CustomReportsBundle’s Sql adapter, which is part of the core open‑source data and experience management platform.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is reported as low probability of exploitation at present, and it is not listed in the CISA KEV catalog. An attacker must be authenticated and possess reports_config access to craft the malicious configuration. Once the report runs, these unchecked inputs reach fetchAll crafted query. This flaw arbitrary database data, compromising confidentiality, integrity, and availability of the underlying data store.
OpenCVE Enrichment
Github GHSA