CVE-2026-23494 | Pimcore up to 11.5.13/12.3.0 API Endpoint staticroutes.php access control (GHSA-m3r2-724c-pwgf)
A vulnerability was found in Pimcore up to 11.5.13/12.3.0. It has been rated as critical. This impacts an unknown function of the file var/config/staticroutes.php of the component API Endpoint. This manipulation causes improper access controls.
This vulnerability appears as CVE-2026-23494. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.