CVE-2026-23495: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-23495 is a Broken Access Control vulnerability (Missing Function Level Authorization) in Pimcore's Admin Classic Bundle, which provides the backend UI for the Pimcore platform. The flaw affects all versions of the 1.x branch prior to 1.7.16 and all 2.x versions from 2.0.0 up to (excluding) 2.2.3. It was disclosed on January 15, 2026, via a GitHub Security Advisory, and patched the same day. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).

Technical details

The root cause is CWE-284 (Improper Access Control): the propertiesAction method in src/Controller/Admin/SettingsController.php only applied the predefined_properties permission check when the request included write/modify data ($request->get('data')), leaving the listing (read) path entirely unprotected. An authenticated backend user could therefore call the Predefined Properties listing API endpoint with their own session cookie and CSRF token — without holding the predefined_properties permission — and receive the full list of property configurations. The fix, committed in PR #1072, moves the $this->checkPermission('predefined_properties') call to the top of the method so it applies unconditionally to all actions, including listing (GitHub Commit, GitHub Advisory).

Impact

Successful exploitation allows any authenticated low-privileged backend user to enumerate all Predefined Properties, exposing internal metadata schemas, property keys, types, and default values that are intended to be restricted by role-based access controls. This information can reveal business logic, data classification strategies, and proprietary configuration details, facilitating reconnaissance for further attacks such as targeted data manipulation or privilege escalation. For organizations managing regulated content (e.g., e-commerce catalogs subject to GDPR or PCI DSS), exposure of these configurations may contribute to compliance breaches or intellectual property leakage. There is no integrity or availability impact; the vulnerability is limited to confidentiality (GitHub Advisory).

Exploitability

A proof-of-concept exploitation path is documented in the official security advisory (classified as 'Exploit, Vendor Advisory' by NVD), demonstrating the steps to reproduce using captured session cookies and CSRF tokens. There is no evidence of active in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is extremely low at 0.00001, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an existing authenticated backend account, significantly limiting the attack surface (GitHub Advisory).

Exploitation steps

  1. Obtain backend credentials: Acquire valid credentials for any low-privileged Pimcore backend user account (e.g., an editor or contributor without property management permissions).
  2. Authenticate and capture tokens: Log in to the Pimcore backend and capture the session Cookie header and X-Pimcore-Csrf-Token value from any authenticated request (e.g., using browser developer tools or a proxy like Burp Suite).
  3. Identify the target endpoint: Using a higher-privileged account or by observing network traffic, identify the API endpoint used to list Predefined Properties (the propertiesAction route in AdminSettingsController).
  4. Replay the request: Send an HTTP GET/POST request to the Predefined Properties listing API endpoint, substituting the low-privileged user's Cookie and X-Pimcore-Csrf-Token values, without including any data parameter.
  5. Retrieve property configurations: The server returns the complete list of Predefined Properties including names, keys, types, and default values, bypassing the intended authorization check (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP requests to the Pimcore Predefined Properties listing API endpoint originating from user accounts that do not hold the predefined_properties permission.
  • Logs: Pimcore access logs showing successful (HTTP 200) responses to the properties listing endpoint for low-privileged user sessions; cross-reference authenticated user identity against permission assignments.
  • Logs: Repeated or scripted calls to the properties API endpoint in a short timeframe from a single session, suggesting automated enumeration rather than normal UI interaction.

Mitigation and workarounds

Pimcore has released patched versions of the Admin Classic Bundle: v1.7.16 for the 1.x branch and v2.2.3 for the 2.x branch. Users should upgrade immediately to the appropriate patched version. No configuration-based workaround is available; the only remediation is upgrading. As a complementary measure, administrators should audit backend user permissions and apply the principle of least privilege, ensuring users only hold permissions necessary for their roles, and monitor API access logs for unauthorized access attempts to the Predefined Properties endpoint (v1.7.16 Release, v2.2.3 Release, GitHub Advisory).

Community reactions

The vulnerability was credited to researcher ytlamal (finder) in the official Pimcore security advisory. A brief technical write-up was published by Infinit Security shortly after disclosure. No significant broader media coverage or notable community debate has been observed, consistent with the moderate severity and limited exploitability of the issue (GitHub Advisory, Infinit Security).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management