Executive brief
Pimcore is a digital experience platform and content management system used to manage websites, assets, and product data. An unauthenticated attacker can hijack any administrator account by injecting a malicious URL into the password reset request, intercepting the recovery token, and using it to gain full administrative access. The attack even bypasses two-factor authentication, allowing complete control over all website content, user accounts, and system configuration.
Technical details
The vulnerability exists in the password reset endpoint (ResetPasswordController.php) which accepts a user-supplied resetPasswordUrl parameter with no validation—no scheme check, domain allowlist, or comparison against configured system domain. The vulnerable UserLoginService concatenates the attacker's URL with a cryptographically valid recovery token and sends it via email before the token is consumed. An attacker can intercept this token by hosting a simple web server at the injected URL. The AdminTokenAuthenticator explicitly disables 2FA when authenticating via token (setTwoFactorAuthentication('required', false)), allowing complete account compromise even on protected admin accounts. The token is valid for 24 hours, single-use, and encrypted with the application secret. No authentication is required to trigger the reset, and the email appears legitimate since it originates from the actual Pimcore server.
Affected products
- Pimcore studio-backend-bundle < 2025.4.6, >= 2026.1.0 and < 2026.1.6
- Pimcore Pimcore 12.x (2026.x branch)
Timeline
- 2026-08-28: disclosed: Vulnerability published to GitHub Advisory Database
- 2026-06-29: patched: Patches released: studio-backend-bundle v2025.4.6 and v2026.1.6
- 2026-07-09: advisory: CVE-2026-55207 published to NVD