SQL injection in Pimcore - CVE-2026-5394
Published: June 15, 2026
Pimcore
Detailed vulnerability description
The vulnerability allows a remote user to modify database schema and cause a denial of service.
The vulnerability exists due to SQL injection in DataObject composite index handling when importing or saving class definitions with crafted composite index metadata. A remote user can supply crafted compositeIndices values to modify database schema and cause a denial of service.
Exploitation requires the ability to import or save DataObject class definitions through the administrative workflow.