fluidattacks.comThird-party advisory
https://fluidattacks.com/es/advisories/dragons CVE-2026-5394
HIGH
Pimcore Platform v12.3.3 - SQL Injection in DataObject composite index handling
Record summary
CVE-2026-5394 has a selected CVSS score of 7.0 (high).
Description
An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 28, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
pimcoreBrowse pimcore / pimcoreDefault status: unaffected | CVE List | 12.3.3 | affected |
pimcore/pimcoreBrowse Packagist / pimcore/pimcore | GitHub Advisory | 12.0.0-RC1 to < 12.3.7 · Fixed in 12.3.7 | affected |
| Before 11.5.17 · Fixed in 11.5.17 | affected | ||
| 2026.1.0 to < 2026.1.3 · Fixed in 2026.1.3 | affected |
References
7github.comproduct
https://github.com/pimcore/pimcore github.com
https://github.com/pimcore/pimcore/commit/6df625ff74015dc11f4bbe76170ce45bbd5dd61d github.compatch
https://github.com/pimcore/pimcore/pull/19108 github.com
https://github.com/pimcore/pimcore/releases/tag/v12.3.7 github.com
https://github.com/pimcore/pimcore/security/advisories/GHSA-r2f4-ff2p-xc64 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-5394