Description
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php and bundles/CustomReportsBundle/src/Tool/Config/Listing/Dao.php, allowing a low-privileged backend user with the reports permission to directly request an unshared report such as poc-secret-report by name and read report name, grouping information, display and icon metadata, data source configuration, column configuration, and sharing settings even when shareGlobally is false. This issue is fixed in versions 11.5.17 (LTS) and 12.3.6.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/pimcore/pimcore/security/advisories/GHSA-jwcc-gv4m-93x6
X_Refsource_Misc x_refsource_misc
https://github.com/pimcore/pimcore/pull/19099
X_Refsource_Misc x_refsource_misc
https://github.com/pimcore/pimcore/commit/1893ff1cd116e442b995ddf17e8c6e0aa372268e
X_Refsource_Misc x_refsource_misc
https://github.com/pimcore/pimcore/releases/tag/v12.3.6
Scores
CVSS v4
7.1
EPSS
0.0031
EPSS Percentile
23.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
pimcore/pimcore
< 11.5.17
pimcore/pimcore
>= 12.0.0, < 12.3.6
Published
Jul 17, 2026
Tracked Since
Jul 18, 2026