Pimcore disclosed and fixed CVE-2026-55207, an account takeover flaw in the password reset workflow that can let an unauthenticated attacker hijack any administrator account and bypass 2FA. The issue stems from insufficient validation of a user-supplied resetPasswordUrl: if an attacker knows a valid admin username, they can trigger a password reset that sends a legitimate recovery token to attacker-controlled infrastructure. If the targeted user clicks the emailed link, the attacker can capture the token and authenticate through the /pimcore-studio/api/login/token endpoint with full administrative privileges.
The vulnerability affects Pimcore versions before 2025.4.6 and versions 2026.1.0 through before 2026.1.6. Pimcore addressed the issue in 2025.4.6 and 2026.1.6; the latter release notes explicitly mention reset password URL validation among the security-relevant changes. The flaw is tracked as CVE-2026-55207, mapped to CWE-640, and carries a high-severity CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-55207 was newly recorded on 2026-07-09 for a Pimcore vulnerability that lets an unauthenticated attacker hijack an admin account by injecting an attacker-controlled resetPasswordUrl into the password reset flow. The issue can lead to full admin access and 2FA bypass, and affects versions before 2025.4.6 and 2026.1.0 through before 2026.1.6.
Pimcore released studio-backend-bundle version 2026.1.6 on 2026-06-29. The release included security-relevant reset password URL validation, which addresses the password reset URL injection issue affecting 2026.1.x versions before 2026.1.6.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.