SQL injection in Pimcore - CVE-2026-55416
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to read, modify, or delete database data.
The vulnerability exists due to improper neutralization of special elements in an SQL command in the Custom Reports bundle Sql adapter\'s buildQueryString() method when processing report configuration fields. A remote user can submit a malicious report configuration to read, modify, or delete database data.
Exploitation requires the reports_config permission.