
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23495 is a Broken Access Control vulnerability (Missing Function Level Authorization) in Pimcore's Admin Classic Bundle, which provides the backend UI for the Pimcore platform. The flaw affects all versions of the 1.x branch prior to 1.7.16 and all 2.x versions from 2.0.0 up to (excluding) 2.2.3. It was disclosed on January 15, 2026, via a GitHub Security Advisory, and patched the same day. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).
The root cause is CWE-284 (Improper Access Control): the propertiesAction method in src/Controller/Admin/SettingsController.php only applied the predefined_properties permission check when the request included write/modify data ($request->get('data')), leaving the listing (read) path entirely unprotected. An authenticated backend user could therefore call the Predefined Properties listing API endpoint with their own session cookie and CSRF token — without holding the predefined_properties permission — and receive the full list of property configurations. The fix, committed in PR #1072, moves the $this->checkPermission('predefined_properties') call to the top of the method so it applies unconditionally to all actions, including listing (GitHub Commit, GitHub Advisory).
Successful exploitation allows any authenticated low-privileged backend user to enumerate all Predefined Properties, exposing internal metadata schemas, property keys, types, and default values that are intended to be restricted by role-based access controls. This information can reveal business logic, data classification strategies, and proprietary configuration details, facilitating reconnaissance for further attacks such as targeted data manipulation or privilege escalation. For organizations managing regulated content (e.g., e-commerce catalogs subject to GDPR or PCI DSS), exposure of these configurations may contribute to compliance breaches or intellectual property leakage. There is no integrity or availability impact; the vulnerability is limited to confidentiality (GitHub Advisory).
A proof-of-concept exploitation path is documented in the official security advisory (classified as 'Exploit, Vendor Advisory' by NVD), demonstrating the steps to reproduce using captured session cookies and CSRF tokens. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is extremely low at 0.00001, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an existing authenticated backend account, significantly limiting the attack surface (GitHub Advisory).
Cookie header and X-Pimcore-Csrf-Token value from any authenticated request (e.g., using browser developer tools or a proxy like Burp Suite).propertiesAction route in AdminSettingsController).Cookie and X-Pimcore-Csrf-Token values, without including any data parameter.predefined_properties permission.Pimcore has released patched versions of the Admin Classic Bundle: v1.7.16 for the 1.x branch and v2.2.3 for the 2.x branch. Users should upgrade immediately to the appropriate patched version. No configuration-based workaround is available; the only remediation is upgrading. As a complementary measure, administrators should audit backend user permissions and apply the principle of least privilege, ensuring users only hold permissions necessary for their roles, and monitor API access logs for unauthorized access attempts to the Predefined Properties endpoint (v1.7.16 Release, v2.2.3 Release, GitHub Advisory).
The vulnerability was credited to researcher ytlamal (finder) in the official Pimcore security advisory. A brief technical write-up was published by Infinit Security shortly after disclosure. No significant broader media coverage or notable community debate has been observed, consistent with the moderate severity and limited exploitability of the issue (GitHub Advisory, Infinit Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."