CVE-2026-44739
Description
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigAction endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php passes malicious SQL configuration through CustomReportController:columnConfigAction, SqlAdapter::getColumns, SqlAdapter::buildQueryString, and Db::fetchAssociative(), allowing an attacker with the reports_config permission to use arbitrary SELECT queries, UNION statements, dangerous database functions, and error-based SQL injection to exfiltrate or manipulate database data. This issue is fixed in versions 11.5.17 (LTS) and 12.3.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pimcore/pimcorePackagist | >= 2026.1.0, < 2026.1.2 | 2026.1.2 |
pimcore/pimcorePackagist | < 11.5.17 | 11.5.17 |
pimcore/pimcorePackagist | >= 12.0.0-RC1, < 12.3.6 | 12.3.6 |
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-3234-gxc3-pq6fghsaADVISORY
- github.com/pimcore/pimcore/commit/3fd7733464f464e58ffa49ed91550c1a3f9535f2nvdWEB
- github.com/pimcore/pimcore/pull/19098nvdWEB
- github.com/pimcore/pimcore/releases/tag/v12.3.6nvdWEB
- github.com/pimcore/pimcore/security/advisories/GHSA-3234-gxc3-pq6fnvdWEB
News mentions
0No linked articles in our index yet.