PKSA-spw3-r32w-35m6 Security Advisory
-
[HIGH] Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
PKSA-spw3-r32w-35m6 CVE-2026-55207 GHSA-h854-c3m3-mh5v
Affected package: pimcore/studio-backend-bundle
Affected version: >=2026.1.0,<2026.1.6|<2025.4.6
Reported by:
GitHub