CVE 8.6 HIGH

Pimcore ENV Variables and Cookie Informations are exposed in http_error_log_CVE-2026-23493

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Description

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensitive information such as database passwords, cookie session data, and other details can be accessed or recovered through the Pimcore backend. This vulnerability is fixed in 12.3.1 and 11.5.14.

AI Analysis

Sensitive information such as database passwords, cookie session data, and other details can be accessed or recovered through the Pimcore backend due to the http_error_log file storing $_COOKIE and $_SERVER variables.

Basic Information

ID CVE-2026-23493
Source GitHub_M
Published Jan 15, 2026 at 16:38

Affected Product

Vendor pimcore
Product pimcore
Version >= 12.0.0-RC1, < 12.3.1
Affected Versions pimcore pimcore >= 12.0.0-RC1, < 12.3.1
pimcore pimcore < 11.5.14

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor Pimcore
Product Pimcore Data & Experience Management Platform
Version 12.0.0-RC1 to 12.3.0, 11.5.13 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.