Description
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of a Custom Reports configuration processed by bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php. The buildQueryString() method concatenates these values into a database query, while a blacklist omits dangerous constructs such as additional data-manipulation statements, comments, subqueries, and multiple statements. The getData() method also previously interpolated offset and limit values into a LIMIT clause without integer casting. Executing the configured report reaches fetchAllAssociative() with the constructed query and can disclose, modify, or delete arbitrary database data. This issue is fixed in versions 11.5.19, 12.3.10, and 2026.1.6.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection enabling disclosure, modification or deletion of arbitrary database data
Action: Immediate Patch
AI Analysis

Impact

An authenticated user with reports_config permission can enter malicious SQL fragments into the sql, from, where, and groupby fields of a Custom Reports configuration in Pimcore. The buildQueryString() method combines these values directly into a SQL statement, relying on a blacklist that only removes a few hazardous constructs, while the getData() method incorrectly inserts offset and limit values into a LIMIT clause without type casting. Running such a report causes the crafted query to be executed through fetchAllAssociative(), allowing the attacker to disclose, modify, or delete arbitrary database data. The vulnerability affects all Pimcore versions prior to 11.5.19, 12.3.10, and 2026.1.6 and is resolved in those releases.

Affected Systems

Pimcore versions prior to 11.5.19, 12.3.10, and 2026.1.6 are affected. The vulnerability resides in the CustomReportsBundle’s Sql adapter, which is part of the core open‑source data and experience management platform.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, indicating high severity. The EPSS score is reported as low probability of exploitation at present, and it is not listed in the CISA KEV catalog. An attacker must be authenticated and possess reports_config access to craft the malicious configuration. Once the report runs, these unchecked inputs reach fetchAll crafted query. This flaw arbitrary database data, compromising confidentiality, integrity, and availability of the underlying data store.

Generated by OpenCVE AI on September 20, 2026 at 23:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Pimcore 11.5.19, 12.3.10, or 2026.1.6 where the flaw is fixed.
  • If a patch cannot permission from all users or restrict it to trusted accounts only.
  • Monitor database logs for unexpected query patterns and, if possible, disable custom report configuration functionality until the patch is deployed.

Generated by OpenCVE AI on September 20, 2026 at 23:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-23rh-xw42-fq82 Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration
History

Tue, 15 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Pimcore
Pimcore pimcore
Vendors & Products Pimcore
Pimcore pimcore

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of a Custom Reports configuration processed by bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php. The buildQueryString() method concatenates these values into a database query, while a blacklist omits dangerous constructs such as additional data-manipulation statements, comments, subqueries, and multiple statements. The getData() method also previously interpolated offset and limit values into a LIMIT clause without integer casting. Executing the configured report reaches fetchAllAssociative() with the constructed query and can disclose, modify, or delete arbitrary database data. This issue is fixed in versions 11.5.19, 12.3.10, and 2026.1.6.
Title Pimcore: SQL Injection in Mautic Custom Reports Bundle Due to Direct Concatenation of User-Controlled Configuration Fields Without Parameterization
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:06:39.915Z

Reserved: 2026-06-16T21:48:43.125Z

Link: CVE-2026-55416

cve-icon Vulnrichment

Updated: 2026-09-14T19:21:26.800Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T17:17:48.220

Modified: 2026-09-16T13:42:48.827

Link: CVE-2026-55416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')