CVE-2026-55207
published 2026-07-09CVE-2026-55207: Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username…
PriorityP260high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.67%
49.6th percentile
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl. The server generates a real cryptographic recovery token, appends it to the supplied URL, and emails the link to the victim; when the victim clicks the link, the token is sent to the attacker and can be used with POST /pimcore-studio/api/login/token to authenticate with full admin privileges while bypassing two-factor authentication. This issue is fixed in versions 2025.4.6 and 2026.1.6.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| pimcore | pimcore | < 2025.4.6 | 2025.4.6 |
| pimcore | pimcore | — | — |
| pimcore | studio-backend-bundle | >= 0 < 2025.4.6 | 2025.4.6 |
| pimcore | studio-backend-bundle | >= 2026.1.0 < 2026.1.6 | 2026.1.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
ghsa·2026-08-28
CVE-2026-55207 [HIGH] CWE-640 Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
## Summary
An unauthenticated attacker takes over any Pimcore admin account by sending a password reset request with an attacker-controlled `resetPasswordUrl`. The server generates a real cryptographic recovery token, appends it to the attacker's URL, and emails the link to the victim. When the victim clicks the link in their email, the token is sent to the attacker's server. The attacker then uses `POST /pimcore-studio/api/login/token` to authenticate as the victim with full admin privileges. Token login explicitly disables two-factor authentication, so even accounts with TOTP/Google Authenticator are compromised.
## Vulnerability Details
### Unauthent
VulDB
Pimcore up to 2025.4.5/2026.1.5 Password Reset token resetPasswordUrl password recovery
vuldb·2026-07-09·CVSS 8.8
CVE-2026-55207 [HIGH] Pimcore up to 2025.4.5/2026.1.5 Password Reset token resetPasswordUrl password recovery
A vulnerability was found in Pimcore up to 2025.4.5/2026.1.5. It has been declared as critical. This impacts the function token of the file /pimcore-studio/api/login/token of the component Password Reset. Executing a manipulation of the argument resetPasswordUrl can lead to weak password recovery.
This vulnerability is registered as CVE-2026-55207. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/pimcore/pimcore/security/advisories/GHSA-h854-c3m3-mh5vhttps://github.com/pimcore/studio-backend-bundle/commit/ea9d329686f5e5aea2eec378d63ac2deb965bb27https://github.com/pimcore/studio-backend-bundle/pull/1882https://github.com/pimcore/studio-backend-bundle/releases/tag/v2025.4.6https://github.com/pimcore/studio-backend-bundle/releases/tag/v2026.1.6https://github.com/pimcore/pimcore/security/advisories/GHSA-h854-c3m3-mh5v
2026-07-09
Published