Improper access control in Pimcore - CVE-2026-45703
Published: June 15, 2026
Pimcore
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the WordExport TranslationController export flow when handling attacker-controlled type/id input for document export. A remote user can request export of a target element without view permission to disclose sensitive information.
For page-like documents, content is rendered in an admin context, which may expose additional backend-visible content.