PT-2026-70137 · Pimcore · Admin Classic Bundle

·

CVE-2026-72562

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pimcore admin-ui-classic-bundle versions prior to 2.4
Description An SQL injection issue exists where authenticated backend users can execute arbitrary SQL commands. This occurs because the filter value in the DataObject grid id column filter is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can use this to exfiltrate or modify all database contents.
Recommendations Update Pimcore admin-ui-classic-bundle to version 2.4 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72562

Affected Products

Admin Classic Bundle