Data Execution Vulnerability in Pimcore Data & Experience Management Platform
CVE-2026-55220
9.3CRITICAL
What is CVE-2026-55220?
The vulnerability in the Pimcore Data & Experience Management Platform arises from a flaw in the Hotspotimage component where it fails to enforce allowed-classes restriction during the deserialization process of PHP serialized bytes. An attacker can exploit this issue by writing malicious serialized data into the object's column, leading to arbitrary file writes or potentially executing code. This vulnerability impacts versions of Pimcore before 11.5.19, 12.3.10, and 2026.1.6, highlighting the need for immediate updates to secure the platform against such threats.
Affected Version(s)
pimcore < 11.5.19 < 11.5.19
pimcore >= 12.0.0-RC1, < 12.3.10 < 12.0.0-RC1, 12.3.10
pimcore >= 2026.1.0, < 2026.1.6 < 2026.1.0, 2026.1.6