Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 5.0 PHP packages GHSA-23rh-xw42-fq82 CVE-2026-55416 PKSA-pmf2-z78s-582m

Pimcore Custom Reports SQL Injection Vulnerability (CVE-2026-55416)

An authenticated SQL injection flaw in Pimcore's Custom Reports bundle allows users with reports_config permission to manipulate database queries, potentially disclosing, modifying, or deleting arbitrary data. Fixed in versions 11.5.19, 12.3.10, and 2026.1.6.

Synthesized by AI from 3 sources · updated 1 hour ago

AI summary

Pimcore, an open source data and experience management platform, has disclosed a SQL injection vulnerability affecting its Custom Reports bundle. Tracked as CVE-2026-55416, the issue allows an authenticated user with the reports_config permission to inject malicious SQL fragments into report configurations, which are then executed against the application's database. The vulnerability has been fixed in Pimcore versions 11.5.19, 12.3.10, and 2026.1.6.

What Happened

A SQL injection vulnerability was identified in Pimcore's Custom Reports functionality. An authenticated user holding the reports_config permission can place attacker-controlled SQL fragments into the sql, from, where, and groupby fields of a Custom Reports configuration. These fields are processed by the Sql.php adapter in the CustomReportsBundle.

Technical Cause

The buildQueryString() method in bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php concatenates user-supplied configuration values directly into a database query. The method relies on a blacklist to filter dangerous input, but this blacklist omits several dangerous constructs, including additional data-manipulation statements, SQL comments, subqueries, and multiple statements. Additionally, the getData() method previously interpolated offset and limit values into a LIMIT clause without casting them to integers, creating an additional injection path. When the configured report is executed, the constructed query reaches fetchAllAssociative(), allowing arbitrary database data to be disclosed, modified, or deleted.

Why It Matters

SQL injection vulnerabilities of this type can lead to full compromise of the confidentiality, integrity, and availability of the underlying database. The CVSS score of 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reflects that the flaw is exploitable over the network with low attack complexity and requires no user interaction, though it does require low-privileged authentication. Since the attacker only needs the reports_config permission rather than full administrative access, this lowers the bar compared to vulnerabilities requiring higher privilege levels.

Who Is Affected

Organizations running pimcore/pimcore with the Custom Reports bundle enabled, where users have been granted the reports_config permission, are affected. The risk is primarily tied to accounts with this specific permission rather than all authenticated users.

Affected Versions

The vulnerability affects pimcore/pimcore versions prior to 11.5.18 (introduced at version 0), versions from 12.0.0 up to and including 12.3.9, and versions from 2026.1.0 up to and including 2026.1.5.

Fixes and Mitigation

Pimcore has released fixes in versions 11.5.19, 12.3.10, and 2026.1.6. These updates address the SQL injection issue in the Custom Reports configuration handling.

Recommended Action

Site owners and developers running affected versions of pimcore/pimcore should upgrade to version 11.5.19, 12.3.10, or 2026.1.6, depending on their current release branch. Until the update can be applied, administrators should review which users hold the reports_config permission and restrict it to trusted accounts only.

PatchBriefing score

5.0 / 10 · Medium

Official CVSS: 8.8

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Why this score

This vulnerability carries a CVSS 3.1 base score of 8.8, calculated from the vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The score reflects network-based exploitability with low attack complexity and no user interaction required, combined with high impact on confidentiality, integrity, and availability. The requirement for low-privileged authentication (PR:L) prevents this from reaching a critical score, but the breadth of potential database impact keeps it in the high severity range. No evidence of known exploitation or public exploit code has been reported, and no EPSS score with meaningful predictive weight was supplied in the fact package beyond a low percentage value.

Affected versions

pimcore/pimcore < 11.5.18
vulnerable
pimcore/pimcore <11.5.18|>=12.0.0-RC1,<=12.3.9|>=2026.1.0,<=2026.1.5
vulnerable
≥ 11.5.19
patched
≥ 12.3.10
patched
≥ 2026.1.6
patched

Reported fixes

Pimcore has released fixes in versions 11.5.19, 12.3.10, and 2026.1.6. These updates address the SQL injection issue in the Custom Reports configuration handling.

How this was built

3 source records were collected, matched and used to prepare the report above.

  • GitHub Advisory Database database
  • Packagist Security Advisories registry
  • NVD (NIST) database
Unified report
Pimcore Custom Reports SQL Injection Vulnerability (CVE-2026-55416)
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email