CVE-2026-45260: Pimcore
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV asset endpoint exposes a MOVE operation through /asset/webdav{path} without an authentication plugin in bundles/CoreBundle/src/Controller/WebDavController.php, and models/Asset/WebDAV/Tree.php performs asset mutation and deletion through models/Asset.php before checking a current Pimcore user or the rename, delete, create, or publish permissions, allowing unauthorized asset deletion, moves, or overwrites. This issue is fixed in versions 11.5.17 (LTS) and 12.3.7.
Affected products
- Pimcore Pimcore: before 11.5.17 (fixed in 11.5.17); from 12.0.0, before 12.3.7 (fixed in 12.3.7)
Published 2026-07-17. Last modified 2026-07-23.