Code Injection Vulnerability in Pimcore Open Source Data Management Platform
CVE-2026-55634
9.9CRITICAL
What is CVE-2026-55634?
The vulnerability in Pimcore allows an authenticated user with object permissions to exploit the class-definition import endpoint. This results in the potential execution of attacker-controlled code through the injection of PHP syntax into generated DataObject classes. The lack of proper validation in the name-setting function exposes the system to malicious inputs, leading to unauthorized code execution in var/classes/DataObject/.php files and modification of SQL identifiers in schema-changing commands. The issue has been rectified in the versions 11.5.19, 12.3.10, and 2026.1.6.
Affected Version(s)
pimcore < 11.5.19 < 11.5.19
pimcore >= 12.0.0-RC1, < 12.3.10 < 12.0.0-RC1, 12.3.10
pimcore >= 2026.1.0, < 2026.1.6 < 2026.1.0, 2026.1.6