CVE-2026-27461: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-27461 is a SQL injection vulnerability in Pimcore, an open-source Data & Experience Management Platform, affecting the dependency listing endpoints. The filter query parameter is JSON-decoded and its value field is concatenated directly into MySQL RLIKE clauses in models/Dependency/Dao.php without sanitization or parameterized queries. Affected versions include all releases up to and including 11.5.14.1 and 12.0.0 through 12.3.2. The vulnerability was published on February 23–24, 2026, with a patch released in version 12.3.3. It carries a CVSS v3.1 base score of 4.9 (Medium) and a CVSS v4.0 base score of 6.9 (Medium), requiring high privileges (admin authentication) to exploit (Github Advisory, Pimcore Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). In models/Dependency/Dao.php, the methods getFilterRequiresByPath() (lines 90, 95, 100) and getFilterRequiredByPath() (lines 148, 153, 158) build SQL queries using direct string concatenation such as "AND LOWER(CONCAT(o.path, o.key)) RLIKE '".$value."'". The entry points are two GET endpoints in ElementController.php: /admin/element/get-requires-dependencies and /admin/element/get-required-by-dependencies, which JSON-decode the filter query parameter and pass $filter['value'] directly to the DAO without escaping. Notably, $orderBy and $orderDirection in the same methods are properly whitelist-validated, but $value has zero sanitization. The fix (PR #18991) replaced all string concatenation with named parameter placeholders (:value, :sourceType, :sourceId) using Doctrine DBAL parameter binding (Pimcore Advisory, Patch Commit).

Impact

An authenticated admin user can exploit this vulnerability to extract the full contents of the underlying MySQL database, including password hashes of all other admin users. The confidentiality impact is high — full database disclosure is achievable via time-based blind or error-based SQL injection techniques. There is no direct integrity or availability impact, but compromised admin password hashes could enable credential cracking and subsequent full platform takeover, potentially leading to lateral movement within the organization's infrastructure (Github Advisory, Pimcore Advisory).

Exploitability

A proof-of-concept (PoC) is publicly available in the GitHub Security Advisory, demonstrating both time-based blind injection (using SLEEP(5)) and error-based data extraction (using extractvalue()). Exploitation requires admin-level authentication, which significantly limits the attack surface. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (2nd percentile), indicating a low probability of near-term exploitation (Github Advisory, Pimcore Advisory).

Exploitation steps

  1. Authenticate as Admin: Obtain valid Pimcore admin credentials (e.g., through phishing, credential stuffing, or insider access) and log into the Pimcore admin panel.
  2. Identify a target element: Note any valid element id (e.g., a document with id=1) accessible within the Pimcore instance to use as the injection anchor.
  3. Time-based blind injection (confirmation): Send the following GET request to confirm vulnerability:
    GET /admin/element/get-requires-dependencies?id=1&elementType=document&filter=[{"type":"string","value":"x' OR SLEEP(5)#"}]
    A response delay of ~15 seconds (SLEEP executes 3 times across UNION arms) confirms the injection point.
  4. Error-based data extraction: Extract database information using:
    GET /admin/element/get-requires-dependencies?id=1&elementType=document&filter=[{"type":"string","value":"x' OR extractvalue(1,concat(0x7e,(SELECT version())))#"}]
    The MySQL version string is returned in the error response.
  5. Dump sensitive data: Craft further error-based or UNION-based payloads to extract tables of interest, such as the users table containing admin password hashes:
    x' OR extractvalue(1,concat(0x7e,(SELECT password FROM users LIMIT 1)))#
  6. Crack password hashes: Use offline tools (e.g., Hashcat, John the Ripper) against extracted hashes to recover plaintext credentials for further access (Pimcore Advisory, Github Advisory).

Indicators of compromise

  • Network: Unusual GET requests to /admin/element/get-requires-dependencies or /admin/element/get-required-by-dependencies containing URL-encoded JSON in the filter parameter with SQL keywords such as SLEEP, extractvalue, UNION, SELECT, or OR.
  • Logs: Web server access logs showing requests to the above endpoints with anomalous filter parameter values; repeated requests with varying payloads from the same authenticated session; unusually long response times (>5 seconds) on dependency listing endpoints suggesting time-based blind injection.
  • Database: MySQL slow query logs showing SLEEP() calls or extractvalue() functions originating from Pimcore's database user; unexpected queries against sensitive tables (e.g., users) from the application layer.
  • Application: Pimcore application logs recording errors related to SQL execution failures or malformed RLIKE expressions, which may indicate failed injection attempts (Pimcore Advisory).

Mitigation and workarounds

Upgrade Pimcore to version 12.3.3 or later (for the 12.x branch) or 11.5.15 or later (for the 11.x branch), which replace vulnerable string concatenation with parameterized queries using Doctrine DBAL parameter binding. As an interim workaround, restrict access to the Pimcore admin panel to trusted IP addresses via network-level controls (firewall rules, VPN), and audit admin user accounts for unauthorized access. Additionally, reset passwords for all administrative users as a precautionary measure, since the vulnerability could have been used to extract existing password hashes (Pimcore Release, Patch PR).

Community reactions

The vulnerability was reported by researcher q1uf3ng and published by Pimcore's security team on February 23, 2026. The fix was developed and merged by Pimcore maintainer kingjia90 on February 19, 2026, prior to public disclosure, indicating a coordinated disclosure process. No significant broader media coverage or notable community debate has been identified beyond standard vulnerability database entries and automated security feeds (Pimcore Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management