CVE-2026-72562

Source
https://cve.org/CVERecord?id=CVE-2026-72562
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72562.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72562
Published
2026-08-11T11:13:02Z
Modified
2026-09-05T03:31:05Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Pimcore pimcore admin-ui-classic-bundle - SQL Injection
Details

An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via the DataObject grid id column filter. The filter value is concatenated directly into the SQL WHERE clause without parameterization. An attacker with backend access can exfiltrate or modify all database contents.

Database specific
{
    "cna_assigner": "TuranSec",
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72562.json"
}
References

Affected packages

Git / github.com/pimcore/admin-ui-classic-bundle

Affected ranges

Type
GIT
Repo
https://github.com/pimcore/admin-ui-classic-bundle
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.3"
        },
        {
            "fixed": "2.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

1.*
1.4.0
2.*
2.0.0-RC2
v1.*
v1.0.0
v1.0.0-BETA1
v1.0.0-RC1
v1.0.0-RC2
v1.1.0
v1.1.0-RC1
v1.1.1
v1.2.0
v1.2.0-RC1
v1.3.0
v1.3.0-RC1
v1.3.1
v1.5.0
v1.5.0-RC1
v1.5.0-RC2
v1.6.0
v1.6.0-RC1
v1.6.0-RC2
v1.7.0
v2.*
v2.0.0
v2.0.0-RC1
v2.0.0-RC2
v2.0.0-RC3
v2.0.0-RC4
v2.1.0
v2.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72562.json"