
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23493 is an information disclosure vulnerability in Pimcore, an Open Source Data & Experience Management Platform, where the http_error_log file stores sensitive PHP superglobals ($_COOKIE and $_SERVER) that can be accessed through the Pimcore backend. It affects all Pimcore versions prior to 11.5.14 (version 11 branch) and versions 12.0.0 through 12.3.0 (version 12 branch). The vulnerability was disclosed on January 15, 2026, via a GitHub Security Advisory. The CNA (GitHub) assigned a CVSS v3.1 score of 8.6 (High), while NVD's assessment yields 4.9 (Medium), reflecting differing assumptions about required privileges (GitHub Advisory).
The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File). Specifically, the ResponseExceptionListener.php in Pimcore's SeoBundle logged the full $_POST, $_COOKIE, and $_SERVER PHP superglobals — including database credentials and session cookies — into the http_error_log database table on every HTTP error event. An attacker with access to the Pimcore backend can navigate to "Search Engine Optimization" → "HTTP Errors," double-click any log entry, and view the stored sensitive data in plaintext. The fix, implemented in PR #18918, removed the logging of parametersPost, cookies, and serverVars columns from the ResponseExceptionListener.php and dropped those columns from the database schema via a migration (GitHub Advisory, Patch Commit).
Successful exploitation allows a Pimcore backend user to recover highly sensitive information including database passwords (from $_SERVER), active session cookies (from $_COOKIE), and other server-side environment variables. Exposure of database credentials could enable unauthorized direct database access, while stolen session cookies could be used for session hijacking to impersonate other users or administrators. This creates a significant risk of lateral movement within the affected infrastructure and potential full platform compromise (GitHub Advisory, Feedly).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is extremely low at 0.000020, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access to the Pimcore backend, which limits the attack surface, though the NVD CNA score of 8.6 assumes no privileges are required based on the advisory's framing.
$_COOKIE, $_SERVER, and $_POST superglobals, potentially exposing database passwords, session tokens, and other environment variables.DATABASE_URL, DB_PASSWORD) from the $_SERVER variables or session cookies from $_COOKIE for use in further attacks such as direct database access or session hijacking (GitHub Advisory, Patch Commit)./admin/misc/http-error-log-detail) — particularly from unusual IP addresses or at unusual times.http_error_log table columns parametersPost, cookies, and serverVars on unpatched installations; these columns should be audited and purged.http_error_log table rather than flat log files (GitHub Advisory).Upgrade Pimcore to version 11.5.14 (for the version 11 branch) or 12.3.1 (for the version 12 branch), which remove the logging of $_POST, $_COOKIE, and $_SERVER from the HTTP error log and drop the corresponding database columns via a migration. Organizations should also audit existing http_error_log table entries for exposed credentials and session data, and rotate any credentials found. As an interim measure, restrict backend access to trusted IP addresses and enforce strong authentication controls to limit who can view the HTTP error log (GitHub Advisory, Patch PR).
The vulnerability was reported by researcher putzflorian and credited in the GitHub Security Advisory. Coverage appeared on The Hacker Wire and was noted on social platforms including Mastodon (infosec.exchange) and Bluesky shortly after disclosure (The Hacker Wire). A technical write-up was also published by Infinitsec (Infinitsec). No significant vendor statements beyond the official advisory or notable researcher controversy have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."