Improper access control in Pimcore admin-ui-classic-bundle - CVE-2023-49075
Published: November 27, 2023 / Updated: July 22, 2026
Pimcore admin-ui-classic-bundle
Detailed vulnerability description
The vulnerability allows a remote user to bypass two-factor authentication.
The vulnerability exists due to improper access control in AdminBundle\Security\PimcoreUserTwoFactorCondition when evaluating non-admin security firewalls. A remote privileged user can access the system without providing two-factor credentials to bypass two-factor authentication.
User interaction is required.