CVE-2026-27461Disclosure(pimcore / pimcore)

LOWCVSS 4.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency listing endpoints is JSON-decoded and the value field is concatenated directly into RLIKE clauses without sanitization or parameterized queries. Exploiting this issue requires admin authentication. An attacker with admin panel access can extract the full database including password hashes of other admin users. Version 12.3.3 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pimcore

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
pimcore

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-25: 1Mentions · 2026-03-25: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 102-2402-2503-25
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1General1
2026-02-251
Disclosure1
2026-03-251
Disclosure1
Full discourse4 posts
  • 秋风@q1uf3ng
    Disclosure

    What are the limits of AI-assisted vulnerability hunting? I obtained 23 CVEs in one month. BentoML 8.2k CVE-2026-27905 HIGH SillyTavern 24.6k CVE-2026-26286 HIGH Plane 28.2k CVE-2026-27705 MEDIUM NocoDB 46.4k CVE-2026-28399 MEDIUM Mautic 8.4k CVE-2026-3105 HIGH File Browser 27.9k CVE-2026-28492 HIGH OpenReplay 7.3k CVE-2026-28443 MEDIUM SuiteCRM 4.0k CVE-2026-29096 HIGH Pimcore 3.6k CVE-2026-27461 HIGH Craft CMS 5.2k CVE-2026-32263 MEDIUM Froxlor 1.6k CVE-2026-30932 HIGH Actual Budget 3.2k CVE-2026-27638 HIGH Lemmy 14.0k CVE-2026-29178 MEDIUM Chartbrew 2.6k CVE-2026-27005 HIGH Tautulli 1.7k CVE-2026-28505 HIGH Typebot 9.5k CVE-2026-33712 CRITICAL LibreChat 34.7k CVE-2026-31942 HIGH Coolify 33.8k CVE-2026-27883 HIGH Gotenberg 3.0k CVE-2026-27018 HIGH Unkey 5.2k CVE-2026-28339 MEDIUM Piwigo 3.3k CVE-2026-27634 CRITICAL Pixelfed 10.7k CVE-2026-27011 HIGH Follow (Folo) 3.0k CVE-2026-27499 HIGH

    Post summary

    The post announces the discovery of 23 CVEs uncovered via AI-assisted vulnerability hunting, providing only identifiers and severity scores without further technical or exploit details.

    720220514825.9K
    1.7K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27461: Pimcore SQL Injection: When 'Enterprise' Logic Meets 'Select * From Disaster' A critical SQL Injection vulnerability in the Pimcore platform allows authenticated administrators to execute arbitrary SQL commands via the dependency listi... https://cvereports.com/reports/CVE-2026-27461

    Post summary

    The report announces a critical SQL injection flaw in Pimcore that lets authenticated admins run arbitrary SQL commands, but no PoC, exploit, or patch details are provided.

    0000037
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27461 Pimcore Admin Panel RLIKE Injection Leading to Database Exposure https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27461

    Post summary

    A new RLIKE injection vulnerability (CVE-2026-27461) in the Pimcore Admin Panel that can expose database contents has been disclosed.

    0000046
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27461 Pimcore is an Open Source Data & Experience Management Platform. In versions up to and including 11.5.14.1 and 12.3.2, the filter query parameter in the dependency li… https://www.cve.org/CVERecord?id=CVE-2026-27461

    Post summary

    The text briefly references CVE-2026-27461 affecting certain Pimcore versions but provides no further details or actionable information.

    0000090
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppimcorepimcore---

Explore more