CVE-2026-5394

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.
CVSS

No CVSS.

Configurations

No configuration.

History

05 May 2026, 18:16

Type Values Removed Values Added
References
  • () https://github.com/pimcore/pimcore/pull/19108 -

27 Apr 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-27 20:16

Updated : 2026-06-17 10:58


NVD link : CVE-2026-5394

Mitre link : CVE-2026-5394

CVE.ORG link : CVE-2026-5394


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')