Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.8epss 0.4%
probabilidad de explotación
0.4%top 72% de las CVE
explotación observada
noninguna fuente lo reporta
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl. The server generates a real cryptographic recovery token, appends it to the supplied URL, and emails the link to the victim; when the victim clicks the link, the token is sent to the attacker and can be used with POST /pimcore-studio/api/login/token to authenticate with full admin privileges while bypassing two-factor authentication. This issue is fixed in versions 2025.4.6 and 2026.1.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Productos afectados
pimcore · pimcoreReferencias
https://github.com/pimcore/pimcore/security/advisories/GHSA-h854-c3m3-mh5vhttps://github.com/pimcore/studio-backend-bundle/commit/ea9d329686f5e5aea2eec378d63ac2deb965bb27https://github.com/pimcore/studio-backend-bundle/pull/1882https://github.com/pimcore/studio-backend-bundle/releases/tag/v2025.4.6https://github.com/pimcore/studio-backend-bundle/releases/tag/v2026.1.6