
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23494 is a Broken Access Control vulnerability in Pimcore, an Open Source Data & Experience Management Platform, classified as "Missing Function Level Authorization on Static Routes Listing." The flaw affects all Pimcore versions prior to 11.5.14 and versions 12.0.0 through 12.3.0 (prior to 12.3.1). It was disclosed on January 15, 2026, via a GitHub Security Advisory. The NVD assigns a CVSS v3.1 base score of 6.5 (Medium), while the CNA (GitHub) scores it at 4.3 (Medium) (GitHub Advisory, NVD).
The root cause is CWE-284 (Improper Access Control): the API endpoint responsible for listing static routes (GET /api/static-routes) does not enforce server-side role-based authorization checks, violating OWASP A01:2021 Broken Access Control (GitHub Advisory). Static routes in Pimcore are custom URL patterns defined via the backend interface or var/config/staticroutes.php, containing regex-based patterns, controller mappings, variables, and priorities, registered via PimcoreStaticRoutesBundle. The fix, merged in PR #18893, removed a redundant permission check and enforced the routes permission (user.isAllowed("routes")) for both read/listing and edit operations at the server side (GitHub PR). Exploitation requires only a valid backend session cookie and CSRF token from any authenticated backend user, regardless of their assigned role permissions.
An authenticated backend user with minimal privileges can invoke GET /api/static-routes and retrieve the full list of static route configurations, exposing internal application architecture including regex URL patterns, controller mappings, route variables, and priorities (GitHub Advisory). This reconnaissance data could facilitate chained attacks such as path traversal, injection via exposed route variables, or discovery of hidden administrative endpoints. In multi-tenant Pimcore environments, exposure of site-specific routing logic may lead to unauthorized data access or workflow manipulation. There is no direct integrity or availability impact; the vulnerability is limited to confidentiality of internal routing metadata.
The vulnerability requires low privileges (any authenticated backend user) and no user interaction, making it straightforward to exploit within an organization's backend user base. The EPSS score is approximately 0.000010 (very low probability of active exploitation), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Feedly). A proof-of-concept is referenced in the GitHub Security Advisory itself (the advisory documents the reproduction steps), and the NVD/CISA-ADP tagged the advisory as "Exploit, Vendor Advisory" (NVD). No threat actor attribution or exploit kit weaponization has been reported.
/admin) and capture the session cookie and X-Pimcore-Csrf-Token header from an authenticated request using a browser proxy tool such as Burp Suite.GET /api/static-routes HTTP request, injecting the captured Cookie and X-Pimcore-Csrf-Token headers from the low-privileged session.GET /api/static-routes requests in web server access logs originating from backend user sessions that do not normally access this endpoint./api/static-routes endpoint being accessed by user accounts without the routes permission; cross-reference user roles against access log entries for this path.Upgrade Pimcore to version 11.5.14 (for the 11.x branch) or 12.3.1 (for the 12.x branch), which enforce proper server-side authorization on the static routes API endpoint (GitHub Release v11.5.14, GitHub Advisory). As an interim measure, restrict backend access to trusted users only and implement network-level controls to limit exposure of the Pimcore admin interface. Review access logs for the /api/static-routes endpoint to identify any unauthorized access that may have already occurred.
The vulnerability was discovered by security researcher ytlamal and reported through GitHub's coordinated disclosure process, with Pimcore publishing the advisory on January 15, 2026 (GitHub Advisory). A brief write-up was published by Infinitsec covering the missing function-level authorization issue (Infinitsec). No significant broader media coverage or notable community debate has been observed given the moderate severity and limited exploitability scope.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."