<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 04:01:26 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-265833</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-265833</link>
      <description>EUVD-2026-265833</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-265833</guid>
    </item>
    <item>
      <title>fkie_cve-2026-23495</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-23495</link>
      <description>&lt;p&gt;Pimcore&amp;#39;s Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore&amp;#39;s official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. The vulnerability is fixed in 2.2.3 and 1.7.16.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Pimcore&amp;#39;s Admin Classic Bundle provides a Backend UI for Pimcore. Prior to 2.2.3 and 1.7.16, the API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore&amp;#39;s official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. The vulnerability is fixed in 2.2.3 and 1.7.16.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-23495</guid>
    </item>
    <item>
      <title>GHSA-hqrp-m84v-2m2f — Pimcore's Admin Classic Bundle is Missing Function Level Authorization on "Predefined Properties" Listing</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hqrp-m84v-2m2f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: pimcore/admin-ui-classic-bundle&lt;/p&gt;
&lt;p&gt;### Summary
The API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore&amp;#39;s official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore&amp;#39;s multi-user environment.&lt;/p&gt;
&lt;p&gt;### Details
The backend user without permission was still able to list &amp;#34;Predefined Properties&amp;#34; item&lt;/p&gt;
&lt;p&gt;### Step to Reproduce the issue 
login as Admin (full permission) and clicked &amp;#34;Predefined Properties&amp;#34;
&amp;lt;img width=&amp;#34;1493&amp;#34; height=&amp;#34;862&amp;#34; alt=&amp;#34;Screenshot 2025-12-10 at 10 11 31 PM&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/005d2704-347c-4aa1-b415-d52ab3794c99&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Then, captured and saved the request:
- List API
&amp;lt;img width=&amp;#34;922&amp;#34; height=&amp;#34;797&amp;#34; alt=&amp;#34;Screenshot 2025-12-10 at 10 39 53 PM&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/2ee3e0e1-06da-442f-b2c7-0dfa8360c04a&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Next, login a backend user with no permission
&amp;lt;img width=&amp;#34;1219&amp;#34; height=&amp;#34;744&amp;#34; alt=&amp;#34;Screenshot 2025-12-1…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: pimcore/admin-ui-classic-bundle&lt;/p&gt;
&lt;p&gt;### Summary
The API endpoint for listing Predefined Properties in the Pimcore platform lacks adequate server-side authorization checks. Predefined Properties are configurable metadata definitions (e.g., name, key, type, default value) used across documents, assets, and objects to standardize custom attributes and improve editorial workflows, as documented in Pimcore&amp;#39;s official properties guide. Testing confirmed that an authenticated backend user without explicit permissions for property management could successfully call the endpoint and retrieve the complete list of these configurations. This exemplifies Broken Access Control (OWASP Top 10 A01:2021), enabling unauthorized access to administrative features and potentially violating role-based access controls inherent to Pimcore&amp;#39;s multi-user environment.&lt;/p&gt;
&lt;p&gt;### Details
The backend user without permission was still able to list &amp;#34;Predefined Properties&amp;#34; item&lt;/p&gt;
&lt;p&gt;### Step to Reproduce the issue 
login as Admin (full permission) and clicked &amp;#34;Predefined Properties&amp;#34;
&amp;lt;img width=&amp;#34;1493&amp;#34; height=&amp;#34;862&amp;#34; alt=&amp;#34;Screenshot 2025-12-10 at 10 11 31 PM&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/005d2704-347c-4aa1-b415-d52ab3794c99&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Then, captured and saved the request:
- List API
&amp;lt;img width=&amp;#34;922&amp;#34; height=&amp;#34;797&amp;#34; alt=&amp;#34;Screenshot 2025-12-10 at 10 39 53 PM&amp;#34; src=&amp;#34;https://github.com/user-attachments/assets/2ee3e0e1-06da-442f-b2c7-0dfa8360c04a&amp;#34; /&amp;gt;&lt;/p&gt;
&lt;p&gt;Next, login a backend user with no permission
&amp;lt;img width=&amp;#34;1219&amp;#34; height=&amp;#34;744&amp;#34; alt=&amp;#34;Screenshot 2025-12-1…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hqrp-m84v-2m2f</guid>
    </item>
  </channel>
</rss>
