NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-5394
Summary

An authenticated administrative user who can import or save DataObject class definitions can inject attacker-controlled composite index metadata and trigger unintended SQL execution in the backend.

This issue affects pimcore: 12.3.3.

Publication Date April 28, 2026, 5:16 a.m.
Registration Date April 29, 2026, 4:07 a.m.
Last Update April 28, 2026, 5:21 a.m.
Related information, measures and tools
Common Vulnerabilities List