
🚨High - Pimcore Admin Account Takeover via Attacker-Controlled Reset URL (CVE-2026-55207) An unauthenticated attacker who knows a valid Pimcore admin username can take over the account by sending a password-reset request with an attacker-controlled resetPasswordUrl. The server generates a real recovery token, appends it to the supplied URL, and emails that link to the victim. When the victim clicks it, the valid token is delivered to the attacker, who can use it with POST /pimcore-studio/api/login/token to authenticate as full admin -bypassing 2FA. Exploitation requires the victim to click the emailed link. 👉Upgrade Pimcore to 2025.4.6 or 2026.1.6.
Post summary
The post highlights a mass‑takeover flaw in Pimcore’s password reset flow and urges users to upgrade to the specified patched releases.
