CVE-2026-23496: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-23496 is a Broken Access Control vulnerability (Missing Function Level Authorization) in the Pimcore Web2Print Tools Bundle, a Composer package that adds web-to-print capabilities to the Pimcore platform. The flaw allows authenticated backend users with low privileges to invoke API endpoints managing "Favourite Output Channel Configurations" without proper server-side authorization checks, enabling unauthorized retrieval and modification of these configurations. It affects all versions of pimcore/web2print-tools-bundle prior to 5.2.2 (5.x branch) and versions 6.0.0 through 6.1.0 (6.x branch). Disclosed on January 15, 2026, it carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Pimcore Advisory).

Technical details

The root cause is improper access control (CWE-284) and incorrect authorization (CWE-863) in the AdminController.php of the Web2Print Tools Bundle. Specifically, the favoriteOutputDefinitionsTableProxyAction method lacked a server-side permission check ($this->checkPermission('web2print_web2print_favourite_output_channels')), meaning the frontend UI correctly hid the feature from unauthorized users, but the backend API endpoint was fully accessible to any authenticated session. An attacker only needs a valid backend session cookie and CSRF token — obtainable by logging in with any low-privileged account — to directly call the List, Create, and Update API endpoints. The fix, merged in PR #108, adds the missing checkPermission() call at the start of the vulnerable controller action (Pimcore Advisory, Fix Commit, PR #108).

Impact

Successful exploitation allows low-privileged authenticated users to view, create, and modify "Favourite Output Channel Configurations" that should be restricted to administrative or operational roles. An attacker could redirect critical print outputs, suppress notifications, insert misleading output channels, or gain reconnaissance into internal print workflows. In regulated environments, this may result in compliance violations or operational disruption. There is no direct availability impact, but confidentiality and integrity of print workflow configurations are both compromised (Pimcore Advisory).

Exploitability

The vulnerability requires authentication with any low-privileged backend account, making it accessible to insider threats or attackers who have obtained valid credentials. The EPSS score is approximately 0.002% (very low), and there is no evidence of in-the-wild exploitation at this time. The GitHub advisory and associated pull request are publicly available and serve as de facto proof-of-concept references, as the reproduction steps are fully documented. The vulnerability is not listed in the CISA KEV catalog (Pimcore Advisory, PR #108).

Exploitation steps

  1. Obtain credentials: Log in to the Pimcore backend with any valid low-privileged user account that does not have explicit permission for the web2print_web2print_favourite_output_channels feature.
  2. Capture session tokens: Using a browser developer tool or proxy (e.g., Burp Suite), capture the session Cookie header and the X-Pimcore-Csrf-Token header from any authenticated backend request.
  3. Identify target endpoints: Using an admin account (or from the advisory's reproduction steps), identify the API endpoints for Favourite Output Channel Configurations — specifically the List, Create, and Update actions in AdminController.php (e.g., /admin/web2print/favorite-output-definitions-table-proxy).
  4. Replay requests with low-privileged session: Substitute the captured low-privileged session cookie and CSRF token into the previously captured admin requests and replay them using a tool like Burp Suite or curl.
  5. Enumerate configurations: Send the List API request to retrieve all existing Favourite Output Channel Configurations, gaining insight into internal print workflow settings.
  6. Modify configurations: Send Create or Update API requests with crafted payloads to insert, alter, or overwrite output channel configurations, potentially redirecting print outputs or disrupting workflows (Pimcore Advisory, PR #108).

Indicators of compromise

  • Network: Unexpected HTTP requests to Pimcore Web2Print admin endpoints (e.g., /admin/web2print/favorite-output-definitions-table-proxy) originating from user accounts that do not have the web2print_web2print_favourite_output_channels permission.
  • Logs: Pimcore access logs showing low-privileged user accounts successfully invoking the favoriteOutputDefinitionsTableProxyAction or saveOrUpdateFavoriteOutputDefinitionAction endpoints; repeated API calls to these endpoints outside of normal business hours.
  • Application Audit: Unexpected creation, modification, or deletion of Favourite Output Channel Configuration entries in the Pimcore database, particularly when correlated with user accounts lacking administrative roles.
  • Session Anomalies: The same session cookie or CSRF token used across multiple IP addresses, which may indicate token theft and replay.

Mitigation and workarounds

Upgrade the pimcore/web2print-tools-bundle Composer package to version 5.2.2 (for the 5.x branch) or 6.1.1 (for the 6.x branch), which add the missing server-side permission check to the vulnerable AdminController actions. No configuration-based workaround is available; patching is the only effective remediation. Administrators should also audit API access logs to determine whether the vulnerable endpoint was accessed by unauthorized users prior to patching (Pimcore Advisory, v5.2.2 Release, v6.1.1 Release).

Community reactions

The vulnerability was discovered by security researcher ytlamal and reported through Pimcore's GitHub security advisory process. The fix was implemented by Pimcore maintainer kingjia90 via PR #108, which was merged on January 13, 2026, ahead of the public disclosure on January 15, 2026. No significant broader media coverage or notable community commentary beyond the GitHub advisory thread has been identified (Pimcore Advisory, PR #108).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management