Data Execution Vulnerability in Pimcore Data & Experience Management Platform
CVE-2026-55220

9.3CRITICAL

Key Information:

Vendor

Pimcore

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55220?

The vulnerability in the Pimcore Data & Experience Management Platform arises from a flaw in the Hotspotimage component where it fails to enforce allowed-classes restriction during the deserialization process of PHP serialized bytes. An attacker can exploit this issue by writing malicious serialized data into the object's column, leading to arbitrary file writes or potentially executing code. This vulnerability impacts versions of Pimcore before 11.5.19, 12.3.10, and 2026.1.6, highlighting the need for immediate updates to secure the platform against such threats.

Affected Version(s)

pimcore < 11.5.19 < 11.5.19

pimcore >= 12.0.0-RC1, < 12.3.10 < 12.0.0-RC1, 12.3.10

pimcore >= 2026.1.0, < 2026.1.6 < 2026.1.0, 2026.1.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.