Code Injection Vulnerability in Pimcore Open Source Data Management Platform
CVE-2026-55634

9.9CRITICAL

Key Information:

Vendor

Pimcore

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55634?

The vulnerability in Pimcore allows an authenticated user with object permissions to exploit the class-definition import endpoint. This results in the potential execution of attacker-controlled code through the injection of PHP syntax into generated DataObject classes. The lack of proper validation in the name-setting function exposes the system to malicious inputs, leading to unauthorized code execution in var/classes/DataObject/.php files and modification of SQL identifiers in schema-changing commands. The issue has been rectified in the versions 11.5.19, 12.3.10, and 2026.1.6.

Affected Version(s)

pimcore < 11.5.19 < 11.5.19

pimcore >= 12.0.0-RC1, < 12.3.10 < 12.0.0-RC1, 12.3.10

pimcore >= 2026.1.0, < 2026.1.6 < 2026.1.0, 2026.1.6

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.