Record summary

CVE-2026-5394 has a selected CVSS score of 7.0 (high).

Description

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend. This issue affects pimcore: 12.3.3.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 28, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List12.3.3affected
GitHub Advisory12.0.0-RC1 to < 12.3.7 · Fixed in 12.3.7affected
Before 11.5.17 · Fixed in 11.5.17affected
2026.1.0 to < 2026.1.3 · Fixed in 2026.1.3affected

References

7