CVE-2026-23493: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-23493 is an information disclosure vulnerability in Pimcore, an Open Source Data & Experience Management Platform, where the http_error_log file stores sensitive PHP superglobals ($_COOKIE and $_SERVER) that can be accessed through the Pimcore backend. It affects all Pimcore versions prior to 11.5.14 (version 11 branch) and versions 12.0.0 through 12.3.0 (version 12 branch). The vulnerability was disclosed on January 15, 2026, via a GitHub Security Advisory. The CNA (GitHub) assigned a CVSS v3.1 score of 8.6 (High), while NVD's assessment yields 4.9 (Medium), reflecting differing assumptions about required privileges (GitHub Advisory).

Technical details

The root cause is classified as CWE-532 (Insertion of Sensitive Information into Log File). Specifically, the ResponseExceptionListener.php in Pimcore's SeoBundle logged the full $_POST, $_COOKIE, and $_SERVER PHP superglobals — including database credentials and session cookies — into the http_error_log database table on every HTTP error event. An attacker with access to the Pimcore backend can navigate to "Search Engine Optimization" → "HTTP Errors," double-click any log entry, and view the stored sensitive data in plaintext. The fix, implemented in PR #18918, removed the logging of parametersPost, cookies, and serverVars columns from the ResponseExceptionListener.php and dropped those columns from the database schema via a migration (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows a Pimcore backend user to recover highly sensitive information including database passwords (from $_SERVER), active session cookies (from $_COOKIE), and other server-side environment variables. Exposure of database credentials could enable unauthorized direct database access, while stolen session cookies could be used for session hijacking to impersonate other users or administrators. This creates a significant risk of lateral movement within the affected infrastructure and potential full platform compromise (GitHub Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (Feedly). The EPSS score is extremely low at 0.000020, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access to the Pimcore backend, which limits the attack surface, though the NVD CNA score of 8.6 assumes no privileges are required based on the advisory's framing.

Exploitation steps

  1. Gain Backend Access: Obtain valid credentials for the Pimcore backend (e.g., through credential theft, phishing, or reuse of exposed credentials from a prior breach).
  2. Navigate to HTTP Error Log: Log into the Pimcore admin interface and navigate to "Search Engine Optimization" → "HTTP Errors" in the backend menu.
  3. Select a Log Entry: Browse the list of HTTP error log entries, which are populated whenever the application encounters HTTP errors (e.g., 404, 500 responses).
  4. View Sensitive Data: Double-click on any log entry to open its detail view. In unpatched versions, the detail view renders the stored $_COOKIE, $_SERVER, and $_POST superglobals, potentially exposing database passwords, session tokens, and other environment variables.
  5. Extract Credentials: Copy database connection strings (e.g., DATABASE_URL, DB_PASSWORD) from the $_SERVER variables or session cookies from $_COOKIE for use in further attacks such as direct database access or session hijacking (GitHub Advisory, Patch Commit).

Indicators of compromise

  • Logs: Pimcore backend access logs showing authenticated requests to the HTTP Error Log detail endpoint (e.g., /admin/misc/http-error-log-detail) — particularly from unusual IP addresses or at unusual times.
  • Database: Presence of sensitive data (database credentials, session tokens) in the http_error_log table columns parametersPost, cookies, and serverVars on unpatched installations; these columns should be audited and purged.
  • Network: Unexpected outbound database connections from the application server originating from non-application processes, which may indicate credential reuse following log data extraction.
  • File System: No direct file artifacts, as the sensitive data is stored in the database http_error_log table rather than flat log files (GitHub Advisory).

Mitigation and workarounds

Upgrade Pimcore to version 11.5.14 (for the version 11 branch) or 12.3.1 (for the version 12 branch), which remove the logging of $_POST, $_COOKIE, and $_SERVER from the HTTP error log and drop the corresponding database columns via a migration. Organizations should also audit existing http_error_log table entries for exposed credentials and session data, and rotate any credentials found. As an interim measure, restrict backend access to trusted IP addresses and enforce strong authentication controls to limit who can view the HTTP error log (GitHub Advisory, Patch PR).

Community reactions

The vulnerability was reported by researcher putzflorian and credited in the GitHub Security Advisory. Coverage appeared on The Hacker Wire and was noted on social platforms including Mastodon (infosec.exchange) and Bluesky shortly after disclosure (The Hacker Wire). A technical write-up was also published by Infinitsec (Infinitsec). No significant vendor statements beyond the official advisory or notable researcher controversy have been identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management