
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23496 is a Broken Access Control vulnerability (Missing Function Level Authorization) in the Pimcore Web2Print Tools Bundle, a Composer package that adds web-to-print capabilities to the Pimcore platform. The flaw allows authenticated backend users with low privileges to invoke API endpoints managing "Favourite Output Channel Configurations" without proper server-side authorization checks, enabling unauthorized retrieval and modification of these configurations. It affects all versions of pimcore/web2print-tools-bundle prior to 5.2.2 (5.x branch) and versions 6.0.0 through 6.1.0 (6.x branch). Disclosed on January 15, 2026, it carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory, Pimcore Advisory).
The root cause is improper access control (CWE-284) and incorrect authorization (CWE-863) in the AdminController.php of the Web2Print Tools Bundle. Specifically, the favoriteOutputDefinitionsTableProxyAction method lacked a server-side permission check ($this->checkPermission('web2print_web2print_favourite_output_channels')), meaning the frontend UI correctly hid the feature from unauthorized users, but the backend API endpoint was fully accessible to any authenticated session. An attacker only needs a valid backend session cookie and CSRF token — obtainable by logging in with any low-privileged account — to directly call the List, Create, and Update API endpoints. The fix, merged in PR #108, adds the missing checkPermission() call at the start of the vulnerable controller action (Pimcore Advisory, Fix Commit, PR #108).
Successful exploitation allows low-privileged authenticated users to view, create, and modify "Favourite Output Channel Configurations" that should be restricted to administrative or operational roles. An attacker could redirect critical print outputs, suppress notifications, insert misleading output channels, or gain reconnaissance into internal print workflows. In regulated environments, this may result in compliance violations or operational disruption. There is no direct availability impact, but confidentiality and integrity of print workflow configurations are both compromised (Pimcore Advisory).
The vulnerability requires authentication with any low-privileged backend account, making it accessible to insider threats or attackers who have obtained valid credentials. The EPSS score is approximately 0.002% (very low), and there is no evidence of in-the-wild exploitation at this time. The GitHub advisory and associated pull request are publicly available and serve as de facto proof-of-concept references, as the reproduction steps are fully documented. The vulnerability is not listed in the CISA KEV catalog (Pimcore Advisory, PR #108).
web2print_web2print_favourite_output_channels feature.Cookie header and the X-Pimcore-Csrf-Token header from any authenticated backend request.AdminController.php (e.g., /admin/web2print/favorite-output-definitions-table-proxy).curl./admin/web2print/favorite-output-definitions-table-proxy) originating from user accounts that do not have the web2print_web2print_favourite_output_channels permission.favoriteOutputDefinitionsTableProxyAction or saveOrUpdateFavoriteOutputDefinitionAction endpoints; repeated API calls to these endpoints outside of normal business hours.Upgrade the pimcore/web2print-tools-bundle Composer package to version 5.2.2 (for the 5.x branch) or 6.1.1 (for the 6.x branch), which add the missing server-side permission check to the vulnerable AdminController actions. No configuration-based workaround is available; patching is the only effective remediation. Administrators should also audit API access logs to determine whether the vulnerable endpoint was accessed by unauthorized users prior to patching (Pimcore Advisory, v5.2.2 Release, v6.1.1 Release).
The vulnerability was discovered by security researcher ytlamal and reported through Pimcore's GitHub security advisory process. The fix was implemented by Pimcore maintainer kingjia90 via PR #108, which was merged on January 13, 2026, ahead of the public disclosure on January 15, 2026. No significant broader media coverage or notable community commentary beyond the GitHub advisory thread has been identified (Pimcore Advisory, PR #108).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."