{"id":"CVE-2026-45260","aliases":["GHSA-wc7j-g8wx-m2qx"],"url":"https://o3.security/vulnerability/CVE-2026-45260","summary":"Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling","details":"Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Controller/WebDavController.php, and models/Asset/WebDAV/Tree.php performs asset mutation and deletion through models/Asset.php before checking a current Pimcore user or the rename, delete, create, or publish permissions, allowing unauthorized asset deletion, moves, or overwrites. This issue is fixed in versions 11.5.17 (LTS) and 12.3.7.","published":"2026-07-17T19:08:38.869Z","modified":"2026-08-12T03:51:16.741047524Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"},"epss":{"score":0.00427,"percentile":0.35664,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"12.3.7"},{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"2026.1.3"},{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"11.5.17"}],"fix":{"url":"https://github.com/pimcore/pimcore/commit/9d7c77fd9b19fa011ce470de95d4438e65007d99","label":"pimcore/pimcore@9d7c77f"},"references":[{"type":"WEB","url":"https://github.com/pimcore/pimcore/releases/tag/v12.3.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45260.json"},{"type":"ADVISORY","url":"https://github.com/pimcore/pimcore/security/advisories/GHSA-wc7j-g8wx-m2qx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45260"},{"type":"FIX","url":"https://github.com/pimcore/pimcore/commit/9d7c77fd9b19fa011ce470de95d4438e65007d99"},{"type":"FIX","url":"https://github.com/pimcore/pimcore/pull/19120"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.741047524Z"}}