CVE-2026-23496

Source
https://cve.org/CVERecord?id=CVE-2026-23496
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23496.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23496
Aliases
Published
2026-01-15T16:58:39.431Z
Modified
2026-07-15T01:49:04.295709311Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Pimcore Web2Print Tools Bundle "Favourite Output Channel Configuration" Missing Function Level Authorization
Details

Pimcore Web2Print Tools Bundle adds tools for web-to-print use cases to Pimcore. Prior to 5.2.2 and 6.1.1, the application fails to enforce proper server-side authorization checks on the API endpoint responsible for managing "Favourite Output Channel Configurations." Testing revealed that an authenticated backend user without explicitely lacking permissions for this feature was still able to successfully invoke the endpoint and modify or retrieve these configurations. This vulnerability is fixed in 5.2.2 and 6.1.1.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23496.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/pimcore/pimcore

Affected ranges

Type
GIT
Repo
https://github.com/pimcore/pimcore
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:pimcore:web2print_tools:*:*:*:*:*:pimcore:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.2.2"
        },
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.1.1"
        }
    ]
}
Type
GIT
Repo
https://github.com/pimcore/web2print-tools
Events
Database specific
{
    "cpe": "cpe:2.3:a:pimcore:web2print_tools:*:*:*:*:*:pimcore:*:*",
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "5.2.2"
        },
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.1.1"
        }
    ]
}

Affected versions

1.*
1.0.0
1.0.1
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.2.0
2.2.1
2.2.2
2.3.0
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.1.0
3.1.1
4.*
4.0.0
4.0.1
4.1.0
4.1.1
4.1.2
4.1.3
4.2.0
4.3.1
4.4.0
4.4.1
4.4.2
4.4.3
v2.*
v2.1.1
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.4.0
v2.4.1
v2.5.0
v2.6.0
v2.7.0
v2.7.1
v2.7.2
v3.*
v3.0.0
v3.1.0
v3.1.1
v3.2.0
v3.2.1
v3.3.0
v3.3.1
v3.4.0
v3.4.1
v3.4.2
v3.4.3
v3.4.4
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.0.3
v5.*
v5.0.0
v5.0.0-BETA1
v5.0.0-BETA2
v5.0.0-RC
v5.0.0-RC1
v5.0.0-RC2
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.1.0
v5.1.0-alpha
v5.1.1
v5.1.2
v5.1.3
v5.2.0
v5.2.0-RC1
v5.2.1
v6.*
v6.0.0
v6.0.1
v6.0.2
v6.0.3
v6.0.4
v6.0.5
v6.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23496.json"