{"id":"CVE-2026-5394","aliases":["GHSA-r2f4-ff2p-xc64"],"url":"https://o3.security/vulnerability/CVE-2026-5394","summary":"Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling","details":"An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend.\n\nThis issue affects pimcore: 12.3.3.","published":"2026-04-27T19:15:04.496Z","modified":"2026-08-12T03:51:43.503247743Z","cvss":null,"epss":{"score":0.00346,"percentile":0.27208,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"12.3.7"},{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"11.5.17"},{"ecosystem":"Packagist","name":"pimcore/pimcore","fixedVersion":"2026.1.3"}],"fix":{"url":"https://github.com/pimcore/pimcore/pull/19108","label":"pimcore/pimcore#19108"},"references":[{"type":"ADVISORY","url":"https://fluidattacks.com/es/advisories/dragons"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5394.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5394"},{"type":"FIX","url":"https://github.com/pimcore/pimcore/pull/19108"},{"type":"PACKAGE","url":"https://github.com/pimcore/pimcore"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.503247743Z"}}