Skip to content
archivevulnerability · 10 Sep 2026 · 19:25 UTC

GHSA-23rh-xw42-fq82: Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration

VULNCVE-2026-55416source · GTH
HIGHHigh-risk vulnerability — CVSS 8.8

last 60 dispatches · spectrum

# Security Advisory: SQL Injection in Custom Reports via Malicious Report Configuration ## Summary ### Impact A SQL injection vulnerability exists in the Custom Reports bundle (`bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php:84-135`). An authenticated attacker with `reports_config` permission can inject arbitrary SQL via the report configuration fields (`sql`, `from`, `where`, `groupby`), which are directly concatenated into SQL queries without parameterization. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected