PT-2026-43629 · Git+2 · Admin Classic Bundle+2
CVE-2026-44741
·
Published
2026-05-27
·
Updated
2026-08-12
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pimcore versions prior to 1.7.18
Pimcore versions prior to 2.3.6
Description
A SQL injection issue exists in the translation grid date filter of the Admin Classic Bundle. The application fails to properly parameterize or validate the
property field provided by the user in the filter JSON, interpolating it directly into a UNIX TIMESTAMP(DATE(FROM UNIXTIME(...))) SQL expression. This occurs at the POST /admin/translation/translations endpoint. An authenticated user with permissions to view translations can exploit this to extract arbitrary database information using UNION-based or error-based techniques. This flaw can be combined with other vulnerabilities to achieve remote code execution.Recommendations
Update Pimcore to version 1.7.18 or later.
Update Pimcore to version 2.3.6 or later.
As a temporary mitigation, restrict access to the
POST /admin/translation/translations endpoint or limit the permissions of users who can access the translations view.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admin Classic Bundle
Pimcore
Pimcore Admin Classic Bundle