CVE-2026-23494: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-23494 is a Broken Access Control vulnerability in Pimcore, an Open Source Data & Experience Management Platform, classified as "Missing Function Level Authorization on Static Routes Listing." The flaw affects all Pimcore versions prior to 11.5.14 and versions 12.0.0 through 12.3.0 (prior to 12.3.1). It was disclosed on January 15, 2026, via a GitHub Security Advisory. The NVD assigns a CVSS v3.1 base score of 6.5 (Medium), while the CNA (GitHub) scores it at 4.3 (Medium) (GitHub Advisory, NVD).

Technical details

The root cause is CWE-284 (Improper Access Control): the API endpoint responsible for listing static routes (GET /api/static-routes) does not enforce server-side role-based authorization checks, violating OWASP A01:2021 Broken Access Control (GitHub Advisory). Static routes in Pimcore are custom URL patterns defined via the backend interface or var/config/staticroutes.php, containing regex-based patterns, controller mappings, variables, and priorities, registered via PimcoreStaticRoutesBundle. The fix, merged in PR #18893, removed a redundant permission check and enforced the routes permission (user.isAllowed("routes")) for both read/listing and edit operations at the server side (GitHub PR). Exploitation requires only a valid backend session cookie and CSRF token from any authenticated backend user, regardless of their assigned role permissions.

Impact

An authenticated backend user with minimal privileges can invoke GET /api/static-routes and retrieve the full list of static route configurations, exposing internal application architecture including regex URL patterns, controller mappings, route variables, and priorities (GitHub Advisory). This reconnaissance data could facilitate chained attacks such as path traversal, injection via exposed route variables, or discovery of hidden administrative endpoints. In multi-tenant Pimcore environments, exposure of site-specific routing logic may lead to unauthorized data access or workflow manipulation. There is no direct integrity or availability impact; the vulnerability is limited to confidentiality of internal routing metadata.

Exploitability

The vulnerability requires low privileges (any authenticated backend user) and no user interaction, making it straightforward to exploit within an organization's backend user base. The EPSS score is approximately 0.000010 (very low probability of active exploitation), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Feedly). A proof-of-concept is referenced in the GitHub Security Advisory itself (the advisory documents the reproduction steps), and the NVD/CISA-ADP tagged the advisory as "Exploit, Vendor Advisory" (NVD). No threat actor attribution or exploit kit weaponization has been reported.

Exploitation steps

  1. Obtain backend credentials: Acquire valid credentials for any Pimcore backend user account, even one with minimal or no explicit permissions assigned.
  2. Authenticate to the backend: Log in to the Pimcore admin interface (e.g., /admin) and capture the session cookie and X-Pimcore-Csrf-Token header from an authenticated request using a browser proxy tool such as Burp Suite.
  3. Craft the API request: Construct a GET /api/static-routes HTTP request, injecting the captured Cookie and X-Pimcore-Csrf-Token headers from the low-privileged session.
  4. Send the request: Submit the request to the target Pimcore instance. The server returns the full list of static route configurations without enforcing role-based access control.
  5. Analyze the response: Review the returned JSON payload for regex URL patterns, controller names, route variables, and priorities to map the application's internal routing structure for use in further targeted attacks (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected or repeated GET /api/static-routes requests in web server access logs originating from backend user sessions that do not normally access this endpoint.
  • Logs: Pimcore backend access logs showing the /api/static-routes endpoint being accessed by user accounts without the routes permission; cross-reference user roles against access log entries for this path.
  • Behavioral: Multiple low-privileged backend accounts querying the static routes API in a short timeframe, potentially indicating automated enumeration or credential sharing.

Mitigation and workarounds

Upgrade Pimcore to version 11.5.14 (for the 11.x branch) or 12.3.1 (for the 12.x branch), which enforce proper server-side authorization on the static routes API endpoint (GitHub Release v11.5.14, GitHub Advisory). As an interim measure, restrict backend access to trusted users only and implement network-level controls to limit exposure of the Pimcore admin interface. Review access logs for the /api/static-routes endpoint to identify any unauthorized access that may have already occurred.

Community reactions

The vulnerability was discovered by security researcher ytlamal and reported through GitHub's coordinated disclosure process, with Pimcore publishing the advisory on January 15, 2026 (GitHub Advisory). A brief write-up was published by Infinitsec covering the missing function-level authorization issue (Infinitsec). No significant broader media coverage or notable community debate has been observed given the moderate severity and limited exploitability scope.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management