8.8
CVE-2026-55207
- EPSS 0.35%
- Veröffentlicht 09.07.2026 21:02:02
- Zuletzt bearbeitet 10.07.2026 15:52:52
- CVE-Watchlists
- Unerledigt
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl. The server generates a real cryptographic recovery token, appends it to the supplied URL, and emails the link to the victim; when the victim clicks the link, the token is sent to the attacker and can be used with POST /pimcore-studio/api/login/token to authenticate with full admin privileges while bypassing two-factor authentication. This issue is fixed in versions 2025.4.6 and 2026.1.6.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerpimcore
≫
Produkt
pimcore
Version
>= 2026.1.0, < 2026.1.6
Status
affected
Version
< 2025.4.6
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.271 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
https://github.com/pimcore/pimcore/security/advisories/GHSA-h854-c3m3-mh5v
https://github.com/pimcore/studio-backend-bundle/pull/1882
https://github.com/pimcore/studio-backend-bundle/commit/ea9d329686f5e5aea2eec378d63ac2deb965bb27
https://github.com/pimcore/studio-backend-bundle/releases/tag/v2025.4.6
https://github.com/pimcore/studio-backend-bundle/releases/tag/v2026.1.6