CVE-2026-55634 and CVE-2026-55220: Critical Pimcore Vulnerabilities
This text was generated using artificial intelligence (AI).On August 28, 2026, two critical vulnerabilities were discovered in pimcore/pimcore published: CVE-2026-55634 with a CVSS v3.1 score of 9.9 and CVE-2026-55220 with a CVSS v4.0 score of 9.3. The vulnerabilities affect different components and each requires different conditions for an attack. The complete technical description is documented in Pimcore's GitHub advisory.
An authenticated user with the permission objects could submit a DataObject field name that was not restricted to valid identifiers. The input could end up in generated PHP properties as well as in SQL identifiers for schema changes.
This made it possible to include PHP syntax in the generated DataObject class files under var/classes/DataObject/ to be included and executed when instantiating the affected classes. In addition, the input could affect SQL identifiers in schema-modifying statements.
This fix resolves the issue of insufficient validation of field names in the affected version series.
CVE-2026-55220: Insecure PHP deserialization in Hotspotimage
CVE-2026-55220 affects Hotspotimage::getDataFromResource. After a failed JSON decoding attempt, the component was unable to retrieve data from the column __hotspots about Pimcore\Tool\Serialize::unserialize process without restricting the permitted classes.
To exploit this, an attacker needs a separate way to write specially crafted serialized PHP data into this column. When a vulnerable DataObject is loaded, available classes can be instantiated and magic methods triggered; this can lead to file-writing operations or code execution via existing gadget chains.
The documented fix affects the caller Hotspot Image. Also Image Gallery, Block and Video use the fallback pattern described above and should be checked for restrictions on permissible classes.
Prioritized Actions
Updating Pimcore: Update installations to version 11.5.19, 12.3.10, or 2026.1.6.
Check for impact: Check the patch status for all production and non-production Pimcore instances, including installations integrated via Packagist.
Limit import rights: Restrict the endpoint for importing class definitions to trusted users. Accounts with the permission objects are particularly relevant to CVE-2026-55634.
Check deserialization patterns: The Callers Image Gallery, Block and Video Check for restrictions on allowed classes during deserialization.
Pimcore is developed by an Austrian provider and is widely used in DACH projects in the e-commerce and PIM sectors. Operators subject to the NIS-2 Directive (in Germany) or the NISG 2026 (in Austria, fully effective as of October 1, 2026) should prioritize checking the patch status of these vulnerabilities. If a personal data breach has occurred, the reporting obligation under GDPR Article 33 may apply (72-hour deadline to notify the competent data protection authority).
Map Externally Accessible Pimcore Instances
Pimcore can be operated as a publicly accessible web application on customer domains. LocateRisk identifies externally accessible systems and identifies the software in use through fingerprints and path patterns such as /pimcore-studio/api/ visible. Since external detection does not allow for immediate identification of the installed version, it is still necessary to verify the version in use to address both vulnerabilities. EASM assists in identifying publicly accessible Pimcore systems and assigning them to the patching process.
In the context of suppliers, C-VRM can report critical vulnerabilities in vendors or changes in their security levels. This allows known dependencies to be factored into the assessment.
Am I affected?
The affected versions are pimcore/pimcore as listed above; the vulnerability has been fixed in versions 11.5.19, 12.3.10, and 2026.1.6. If you want to know whether pimcore/pimcore is even visible on your own externally accessible infrastructure, you can use the CVE Quick Check Use the tool at the end of this article: It shows exposed systems and the software that is visible from the outside.
It is not always possible to determine the specific version that has been installed from the outside—the key factor is comparing it with the manufacturer's advisory.
CVE-2026-55634 is a critical vulnerability (CVSS v3.1: 9.9) in Pimcore's class definition import endpoint. An authenticated user with the permission objects can inject PHP syntax into generated DataObject class files, which is executed when the class is instantiated.
The most important action is to update to 11.5.19, 12.3.10, or 2026.1.6. In addition, the import endpoint for class definitions should be restricted to trusted users, and the patch status of all instances—including those integrated via Packagist—should be checked.
As of August 29, 2026. This article is intended for general informational purposes only and does not constitute legal, security, or operational advice in specific cases. The security situation and patch availability may have changed since publication; the linked manufacturer advisory is always authoritative. Despite careful research, we do not guarantee that the information is up-to-date, accurate, or complete.
CVE Quick Check
In just a few minutes, check whether there are any indications of a current CVE on your externally visible attack surface.
A rough estimate in just a few minutes via email.
Learn more during a free consultation with a LocateRisk consultant.
You'll receive this by email
companyYour Company, LLC
Verified CVECVE-2024-3094
Passive Assessment
Information About the CVENotes found
Want to find out more, book a demo or simply exchange ideas? We look forward to hearing from you!
We use cookies to optimize our website and our service.
Functional
Always active
Technical storage or access is strictly necessary for the lawful purpose of enabling the use of a particular service expressly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a message over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that have not been requested by the subscriber or user.
Statistics
The technical storage or access, which is carried out exclusively for statistical purposes.Technical storage or access used solely for anonymous statistical purposes. Without a subpoena, the voluntary consent of your Internet service provider, or additional records from third parties, information stored or accessed for this purpose alone generally cannot be used to identify you.
Marketing
Technical storage or access is necessary to create user profiles, to send advertisements, or to track the user on a website or across multiple websites for similar marketing purposes.