{"id":"CVE-2026-23493","aliases":["GHSA-q433-j342-rp9h"],"url":"https://o3.security/vulnerability/CVE-2026-23493","summary":"Pimcore ENV Variables and Cookie Informations are exposed in http_error_log","details":"### Summary\nThe http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and other details can be accessed or recovered through the Pimcore backend.\n\n### Details\nIt’s better to remove both lines, as this information makes little sense in this context anyway.\n\nhttps://github.com/pimcore/pimcore/blob/12.x/bundles/SeoBundle/src/EventListener/ResponseExceptionListener.php#L92\nhttps://github.com/pimcore/pimcore/blob/12.x/bundles/SeoBundle/src/EventListener/ResponseExceptionListener.php#L93\n\n### PoC\nIn the Pimcore backend, navigate to \"Search Engine Optimization\" and click on \"HTTP Errors.\" Double-click on an entry to view its details. Here, you may find sensitive data exposed.\n\n### Impact\nPimcore backend users can access sensitive environment variables, potentially exposing critical information.","published":"2026-01-15T16:38:23.923Z","modified":"2026-08-12T03:51:48.661404668Z","cvss":{"score":8.6,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"},"epss":{"score":0.00393,"percentile":0.3198,"asOf":"2026-08-05"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"12.3.1"},{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"11.5.14"}],"fix":{"url":"https://github.com/pimcore/pimcore/commit/002ec7d5f84973819236796e5b314703b58e8601","label":"pimcore/pimcore@002ec7d"},"references":[{"type":"WEB","url":"https://github.com/pimcore/pimcore/releases/tag/v11.5.14"},{"type":"WEB","url":"https://github.com/pimcore/pimcore/releases/tag/v12.3.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23493.json"},{"type":"ADVISORY","url":"https://github.com/pimcore/pimcore/security/advisories/GHSA-q433-j342-rp9h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23493"},{"type":"FIX","url":"https://github.com/pimcore/pimcore/commit/002ec7d5f84973819236796e5b314703b58e8601"},{"type":"FIX","url":"https://github.com/pimcore/pimcore/pull/18918"},{"type":"PACKAGE","url":"https://github.com/pimcore/pimcore"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.661404668Z"}}