CVE Explorer
CVE-2026-23493
Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and other details can be accessed or recovered through the Pimcore backend. This vulnerability is fixed in 12.3.1 and 11.5.14.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"pimcore","vendor":"pimcore","versions":[{"status":"affected","version":">= 12.0.0-RC1, < 12.3.1"},{"status":"affected","version":"< 11.5.14"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:70776dd24e9a087184651ecd3913a4416f2d9ebd073de1fa6ed9a9e523b0b4f5 · sha256:4d47fe2a09a58d5e… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.6,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:70776dd24e9a087184651ecd3913a4416f2d9ebd073de1fa6ed9a9e523b0b4f5 · sha256:4d47fe2a09a58d5e… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-532","description":"CWE-532: Insertion of Sensitive Information into Log File","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:70776dd24e9a087184651ecd3913a4416f2d9ebd073de1fa6ed9a9e523b0b4f5 · sha256:4d47fe2a09a58d5e… · /containers/cna/problemTypes/0/descriptions/0
Source references
6 source assertions{"name":"https://github.com/pimcore/pimcore/commit/002ec7d5f84973819236796e5b314703b58e8601","tags":["x_refsource_MISC"],"url":"https://github.com/pimcore/pimcore/commit/002ec7d5f84973819236796e5b314703b58e8601"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:70776dd24e9a087184651ecd3913a4416f2d9ebd073de1fa6ed9a9e523b0b4f5 · sha256:4d47fe2a09a58d5e… · /containers/cna/references/2
{"name":"https://github.com/pimcore/pimcore/pull/18918","tags":["x_refsource_MISC"],"url":"https://github.com/pimcore/pimcore/pull/18918"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:70776dd24e9a087184651ecd3913a4416f2d9ebd073de1fa6ed9a9e523b0b4f5 · sha256:4d47fe2a09a58d5e… · /containers/cna/references/1
{"name":"https://github.com/pimcore/pimcore/releases/tag/v11.5.14","tags":["x_refsource_MISC"],"url":"https://github.com/pimcore/pimcore/releases/tag/v11.5.14"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:70776dd24e9a087184651ecd3913a4416f2d9ebd073de1fa6ed9a9e523b0b4f5 · sha256:4d47fe2a09a58d5e… · /containers/cna/references/3
{"name":"https://github.com/pimcore/pimcore/releases/tag/v12.3.1","tags":["x_refsource_MISC"],"url":"https://github.com/pimcore/pimcore/releases/tag/v12.3.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:70776dd24e9a087184651ecd3913a4416f2d9ebd073de1fa6ed9a9e523b0b4f5 · sha256:4d47fe2a09a58d5e… · /containers/cna/references/4
{"name":"https://github.com/pimcore/pimcore/security/advisories/GHSA-q433-j342-rp9h","tags":["x_refsource_CONFIRM"],"url":"https://github.com/pimcore/pimcore/security/advisories/GHSA-q433-j342-rp9h"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:70776dd24e9a087184651ecd3913a4416f2d9ebd073de1fa6ed9a9e523b0b4f5 · sha256:4d47fe2a09a58d5e… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/pimcore/pimcore/security/advisories/GHSA-q433-j342-rp9h"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:70776dd24e9a087184651ecd3913a4416f2d9ebd073de1fa6ed9a9e523b0b4f5 · sha256:4d47fe2a09a58d5e… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.