CVE-2026-55207
Last modified
CVE-2026-55207 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl. The server generates a real cryptographic recovery token, appends it to the supplied URL, and emails the link to the victim; when the victim clicks the link, the token is sent to the attacker and can be used with POST /pimcore-studio/api/login/token to authenticate with full admin privileges while bypassing two-factor authentication. This issue is fixed in versions 2025.4.6 and 2026.1.6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| pimcore | pimcore | >= 2026.1.0, < 2026.1.6; < 2025.4.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55207?
How severe is CVE-2026-55207?
How do I fix CVE-2026-55207?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55201Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a …7.4
- CVE-2026-55202Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to …8.8
- CVE-2026-55203HAProxy through 3.4.0, fixed in commit 5985276, contains an …9.1
- CVE-2026-55204HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a …8.7
- CVE-2026-55205Hermes WebUI before 0.51.468 contains a resource exhaustion …6.9
- CVE-2026-55206py7zr is a Python-based library and utility to support 7zip …8.7
- CVE-2026-55208Pimcore Studio Backend Bundle is the backend bundle for Pimc…7.7
- CVE-2026-55212Pimcore is an Open Source Data & Experience Management Platf…7.1
- CVE-2026-55213h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and …7.5
- CVE-2026-55219Paymenter is a free and open-source webshop solution for man…5.3
- CVE-2026-55223c3p0 is a JDBC Connection pooling library. In versions prior…6.3
- CVE-2026-55229Gotenberg is a Docker-powered stateless API for PDF files. P…7.5
Are you affected by CVE-2026-55207?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
