<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T07:51:10.997047+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265833</id>
    <title>EUVD-2026-265833</title>
    <updated>2026-10-09T07:51:11.060299+00:00</updated>
    <content>EUVD-2026-265833</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265833"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23495</id>
    <title>fkie_cve-2026-23495</title>
    <updated>2026-10-09T07:51:11.060337+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. The vulnerability is fixed in 2.2.3 and 1.7.16.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-23495"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hqrp-m84v-2m2f</id>
    <title>GHSA-hqrp-m84v-2m2f — Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing</title>
    <updated>2026-10-09T07:51:11.060376+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: pimcore/admin-ui-classic-bundle</p>
<p>### Summary
The API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore's official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore's multi-user environment.</p>
<p>### Details
The backend user without permission was still able to list "Predefined Properties" item</p>
<p>### Step to Reproduce the issue 
login as Admin (full permission) and clicked "Predefined Properties"
&lt;img width="1493" height="862" alt="Screenshot 2025-12-10 at 10 11 31 PM" src="https://github.com/user-attachments/assets/005d2704-347c-4aa1-b415-d52ab3794c99" /&gt;</p>
<p>Then, captured and saved the request:
- List API
&lt;img width="922" height="797" alt="Screenshot 2025-12-10 at 10 39 53 PM" src="https://github.com/user-attachments/assets/2ee3e0e1-06da-442f-b2c7-0dfa8360c04a" /&gt;</p>
<p>Next, login a backend user with no permission
&lt;img width="1219" height="744" alt="Screenshot 2025-12-1…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hqrp-m84v-2m2f"/>
  </entry>
</feed>
