PT-2026-43629 · Git+2 · Admin Classic Bundle+2

CVE-2026-44741

·

Published

2026-05-27

·

Updated

2026-08-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pimcore versions prior to 1.7.18 Pimcore versions prior to 2.3.6
Description A SQL injection issue exists in the translation grid date filter of the Admin Classic Bundle. The application fails to properly parameterize or validate the property field provided by the user in the filter JSON, interpolating it directly into a UNIX TIMESTAMP(DATE(FROM UNIXTIME(...))) SQL expression. This occurs at the POST /admin/translation/translations endpoint. An authenticated user with permissions to view translations can exploit this to extract arbitrary database information using UNION-based or error-based techniques. This flaw can be combined with other vulnerabilities to achieve remote code execution.
Recommendations Update Pimcore to version 1.7.18 or later. Update Pimcore to version 2.3.6 or later. As a temporary mitigation, restrict access to the POST /admin/translation/translations endpoint or limit the permissions of users who can access the translations view.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44741
GHSA-H4PH-CRVJ-9H92

Affected Products

Admin Classic Bundle
Pimcore
Pimcore Admin Classic Bundle