{"id":99109,"date":"2026-08-29T00:00:33","date_gmt":"2026-08-28T22:00:33","guid":{"rendered":"https:\/\/locaterisk.com\/de\/?p=99109"},"modified":"2026-08-29T00:00:33","modified_gmt":"2026-08-28T22:00:33","slug":"pimcore-cve-2026-55634","status":"publish","type":"post","link":"https:\/\/locaterisk.com\/en\/pimcore-cve-2026-55634\/","title":{"rendered":"CVE-2026-55634 and CVE-2026-55220: Critical Pimcore Vulnerabilities"},"content":{"rendered":"\n<div class=\"wp-block-lr-blog-article-header-module\">\n    <div class=\"content\">\n\t\t<div class=\"headline\">\n\t\t\t<a class=\"to-blog-button\" href=\"https:\/\/locaterisk.com\/en\/blog\/\">\n\t\t\t\t<span class=\"to-blog-arrow\" aria-hidden=\"true\">\u2190<\/span>\n\t\t\t\t<span>Back to blog<\/span>\n\t\t\t<\/a>\n\t\t\t<div class=\"article-meta\">\n\t\t\t\t\t\t\t\t\t<p class=\"post-updated\">Published: August 29, 2026<\/p>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n        <div class=\"main-content\">\n\t\t\t<h1 class=\"title\">CVE-2026-55634 und CVE-2026-55220: Kritische Pimcore-Schwachstellen<\/h1>\n\t\t\t\t\t\t\t<p class=\"paragraph\"><span class=\"lr-ai-disclosure\" style=\"margin:8px 0 28px;font-size:14px;line-height:1.4;color:#8b93a7;font-family:inherit;font-style:italic\">Dieser Text wurde mit k\u00fcnstlicher Intelligenz (KI) erstellt.<\/span>Am 28. August 2026 wurden zwei kritische Schwachstellen in <strong>pimcore\/pimcore<\/strong> ver\u00f6ffentlicht: <strong>CVE-2026-55634<\/strong> mit einem CVSS-v3.1-Score von <strong>9.9<\/strong> und <strong>CVE-2026-55220<\/strong> mit einem CVSS-v4.0-Score von <strong>9.3<\/strong>. Die Fehler betreffen unterschiedliche Komponenten und setzen jeweils andere Voraussetzungen f\u00fcr einen Angriff voraus. Die vollst\u00e4ndige technische Beschreibung ist im GitHub Advisory von Pimcore dokumentiert.<br><br><a href=\"#cve-check\" class=\"lr-cveqc-jump\" style=\"font-weight:700;color:#26d9c3;text-decoration:none\">Sind meine Systeme betroffen? Jetzt pr\u00fcfen \u2192<\/a><\/p>\n\t\t\t        <\/div>\n    <\/div>\n<\/div>\n\n\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"400\" height=\"400\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png\" alt=\"CVE-2026-55634 und CVE-2026-55220: Kritische Pimcore-Schwachstellen\" class=\"wp-image-9138\" srcset=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png 400w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure-300x300.png 300w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure-150x150.png 150w, https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure-12x12.png 12w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\" \/><\/figure><\/div>\n\n\n<p><strong>Auf einen Blick:<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Produkt \/ Komponente<\/th><th>Betroffene Versionen<\/th><th>Gepatcht in<\/th><\/tr><\/thead><tbody><tr><td>pimcore\/pimcore<\/td><td><11.5.19, <12.3.10, <2026.1.6<\/td><td>11.5.19, 12.3.10, 2026.1.6<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Schwachstelle: <strong>CVE-2026-55634<\/strong> (<strong>CVSS 9.9<\/strong>, kritisch); weitere: <strong>CVE-2026-55220<\/strong><\/li>\n\n\n\n<li>Status: kein aktiver Missbrauch belegt<\/li>\n\n\n\n<li>Patch verf\u00fcgbar seit: 28.08.2026<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u00dcberblick<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Schwachstelle<\/th><th>Technischer Bereich<\/th><th>Voraussetzung<\/th><th>Fehlerbereinigte Versionen<\/th><\/tr><\/thead><tbody><tr><td>CVE-2026-55634<\/td><td>Import von Klassendefinitionen<\/td><td>Authentifiziertes Konto mit der Berechtigung <strong>objects<\/strong><\/td><td>11.5.19, 12.3.10, 2026.1.6<\/td><\/tr><tr><td>CVE-2026-55220<\/td><td>PHP-Deserialisierung bei <strong>Hotspotimage<\/strong><\/td><td>Separate M\u00f6glichkeit, pr\u00e4parierte serialisierte PHP-Daten in die betroffene Spalte zu schreiben<\/td><td>11.5.19, 12.3.10, 2026.1.6<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Betroffen sind Pimcore-Installationen vor <strong>11.5.19<\/strong>, <strong>12.3.10<\/strong> oder <strong>2026.1.6<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>CVE-2026-55634: Code-Injection \u00fcber den Import von Klassendefinitionen<\/strong><\/h2>\n\n\n\n<p>CVE-2026-55634 betrifft den Import-Endpunkt f\u00fcr Klassendefinitionen:<\/p>\n\n\n\n<p><strong>\/pimcore-studio\/api\/class\/definition\/configuration-view\/detail\/{id}\/import<\/strong><\/p>\n\n\n\n<p>Ein authentifizierter Nutzer mit der Berechtigung <strong>objects<\/strong> konnte einen DataObject-Feldnamen \u00fcbermitteln, der nicht auf zul\u00e4ssige Bezeichner begrenzt war. Die Eingabe konnte in erzeugte PHP-Properties sowie in SQL-Bezeichner f\u00fcr Schema\u00e4nderungen gelangen.<\/p>\n\n\n\n<p>Dadurch war es m\u00f6glich, PHP-Syntax in erzeugte DataObject-Klassendateien unter <strong>var\/classes\/DataObject\/<\/strong> einzubringen und bei der Instanziierung betroffener Klassen auszuf\u00fchren. Zus\u00e4tzlich konnte die Eingabe SQL-Bezeichner in schema\u00e4ndernden Anweisungen beeinflussen.<\/p>\n\n\n\n<p>Die Korrektur schlie\u00dft die unzureichende Validierung von Feldnamen in den betroffenen Versionsreihen.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>CVE-2026-55220: Unsichere PHP-Deserialisierung bei Hotspotimage<\/strong><\/h2>\n\n\n\n<p>CVE-2026-55220 betrifft <strong>Hotspotimage::getDataFromResource<\/strong>. Nach einem fehlgeschlagenen JSON-Decoding konnte die Komponente Daten aus der Spalte <strong>__hotspots<\/strong> \u00fcber <strong>Pimcore\\Tool\\Serialize::unserialize<\/strong> verarbeiten, ohne die zul\u00e4ssigen Klassen einzuschr\u00e4nken.<\/p>\n\n\n\n<p>Ein Angreifer ben\u00f6tigt hierf\u00fcr eine separate M\u00f6glichkeit, pr\u00e4parierte serialisierte PHP-Daten in diese Spalte zu schreiben. Beim Laden eines betroffenen DataObject k\u00f6nnen verf\u00fcgbare Klassen instanziiert und Magic Methods ausgel\u00f6st werden; \u00fcber vorhandene Gadget Chains k\u00f6nnen daraus Dateischreibvorg\u00e4nge oder Code-Ausf\u00fchrung entstehen.<\/p>\n\n\n\n<p>Die dokumentierte Korrektur betrifft den Aufrufer <strong>Hotspotimage<\/strong>. Auch <strong>ImageGallery<\/strong>, <strong>Block<\/strong> und <strong>Video<\/strong> verwenden das beschriebene Fallback-Muster und sollten auf Einschr\u00e4nkungen zul\u00e4ssiger Klassen gepr\u00fcft werden.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Priorisierte Ma\u00dfnahmen<\/strong><\/h2>\n\n\n\n<ol class=\"wp-block-list has-text-color\" style=\"color:#ffffff\">\n<li><strong>Pimcore aktualisieren:<\/strong> Installationen auf 11.5.19, 12.3.10 oder 2026.1.6 aktualisieren.<\/li>\n\n\n\n<li><strong>Betroffenheit pr\u00fcfen:<\/strong> Den Patchstatus f\u00fcr alle produktiven und nichtproduktiven Pimcore-Instanzen pr\u00fcfen, einschlie\u00dflich \u00fcber Packagist eingebundener Installationen.<\/li>\n\n\n\n<li><strong>Importrechte begrenzen:<\/strong> Den Endpunkt f\u00fcr den Import von Klassendefinitionen auf vertrauensw\u00fcrdige Nutzer beschr\u00e4nken. Konten mit der Berechtigung <strong>objects<\/strong> sind f\u00fcr CVE-2026-55634 besonders relevant.<\/li>\n\n\n\n<li><strong>Deserialisierungsmuster pr\u00fcfen:<\/strong> Die Aufrufer <strong>ImageGallery<\/strong>, <strong>Block<\/strong> und <strong>Video<\/strong> auf Beschr\u00e4nkungen zul\u00e4ssiger Klassen bei der Deserialisierung pr\u00fcfen.<\/li>\n<\/ol>\n\n\n\n<p>Pimcore wird von einem \u00f6sterreichischen Anbieter entwickelt und ist in DACH-Projekten im E-Commerce- und PIM-Umfeld verbreitet. Betreiber, die unter die NIS-2-Richtlinie (in Deutschland) oder das NISG 2026 (in \u00d6sterreich, vollwirksam ab 1. Oktober 2026) fallen, sollten den Patchstatus dieser Schwachstellen priorisiert pr\u00fcfen. Sofern ein Vorfall mit Personenbezug eingetreten ist, gilt ggf. die Meldepflicht nach DSGVO Art. 33 (72-Stunden-Frist an die zust\u00e4ndige Datenschutzbeh\u00f6rde).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Extern erreichbare Pimcore-Instanzen zuordnen<\/strong><\/h2>\n\n\n\n<p>Pimcore kann unter Kunden-Domains als \u00f6ffentlich erreichbare Webanwendung betrieben werden. LocateRisk erfasst extern erreichbare Systeme und macht eingesetzte Software \u00fcber Fingerprints und Pfadmuster wie <strong>\/pimcore-studio\/api\/<\/strong> sichtbar. Da die externe Erkennung keinen unmittelbaren R\u00fcckschluss auf den installierten Versionsstand erlaubt, bleibt die Pr\u00fcfung der eingesetzten Version f\u00fcr die Behandlung beider Schwachstellen erforderlich. EASM unterst\u00fctzt bei der Erfassung \u00f6ffentlich erreichbarer Pimcore-Systeme und bei deren Zuordnung zum Patchprozess.<\/p>\n\n\n\n<p>Im Lieferantenkontext kann C-VRM kritische Schwachstellen bei Anbietern oder Ver\u00e4nderungen ihres Sicherheitsniveaus melden. Damit lassen sich bekannte Abh\u00e4ngigkeiten in die Bewertung einbeziehen.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Bin ich betroffen?<\/strong><\/h2>\n\n\n\n<p>Betroffen ist pimcore\/pimcore in den oben genannten Versionen; behoben wurde die Schwachstelle in 11.5.19, 12.3.10, 2026.1.6. Wer wissen will, ob pimcore\/pimcore in der eigenen extern erreichbaren Infrastruktur \u00fcberhaupt sichtbar ist, kann den <a href=\"#cve-check\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-Quick-Check<\/a> am Ende dieses Artikels nutzen: Er zeigt exponierte Systeme und die von au\u00dfen erkennbare Software.<\/p>\n\n\n\n<p>Die konkret installierte Version l\u00e4sst sich von au\u00dfen nicht in jedem Fall bestimmen \u2014 ausschlaggebend ist der Abgleich mit dem Hersteller-Advisory.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Quellen und weitere Infos<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>GitHub Advisory (Pimcore):<\/strong> <a href=\"https:\/\/github.com\/pimcore\/pimcore\/security\/advisories\/GHSA-9x44-4gxf-8c25\" target=\"_blank\" rel=\"noreferrer noopener\">GHSA-9&#215;44-4gxf-8c25 \u2014 CVE-2026-55634 &#038; CVE-2026-55220<\/a><\/li>\n\n\n\n<li><strong>GitHub Advisory (Pimcore):<\/strong> <a href=\"https:\/\/github.com\/pimcore\/pimcore\/security\/advisories\/GHSA-w23p-wrp7-ch38\" target=\"_blank\" rel=\"noreferrer noopener\">GHSA-w23p-wrp7-ch38<\/a><\/li>\n\n\n\n<li><strong>GitHub:<\/strong> <a href=\"https:\/\/github.com\/pimcore\/pimcore\/pull\/19183\" target=\"_blank\" rel=\"noreferrer noopener\">Pimcore Pull Request 19183<\/a><\/li>\n\n\n\n<li><strong>GitHub:<\/strong> <a href=\"https:\/\/github.com\/pimcore\/pimcore\/releases\/tag\/v2026.1.6\" target=\"_blank\" rel=\"noreferrer noopener\">Pimcore Release v2026.1.6<\/a><\/li>\n<\/ul>\n\n\n\n<div class=\"wp-block-lr-faq-module\"><div class=\"content\"><h3><strong>H\u00e4ufige Fragen<\/strong><\/h3><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Was ist CVE-2026-55634?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">CVE-2026-55634 ist eine kritische Schwachstelle (CVSS v3.1: 9.9) im Import-Endpunkt f\u00fcr Klassendefinitionen von Pimcore. Ein authentifizierter Nutzer mit der Berechtigung <strong>objects<\/strong> kann PHP-Syntax in erzeugte DataObject-Klassendateien einschleusen, die beim Instanziieren der Klasse ausgef\u00fchrt wird.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Welche Pimcore-Versionen sind von CVE-2026-55634 und CVE-2026-55220 betroffen?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Betroffen sind alle Pimcore-Installationen vor den Versionen 11.5.19, 12.3.10 und 2026.1.6. Beide Schwachstellen sind in diesen Versionen behoben.<\/p><\/div><\/div><div class=\"faq-topic\"><hr\/><div class=\"collapsible-title\"><a class=\"pr-4\"><strong>Wie sch\u00fctze ich meine Pimcore-Installation?<\/strong><\/a><img class=\"collapse-toggle\" srcset=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@3x.png 3x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus@2x.png 2x,https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/faq-module\/img\/ic-plus.png 1x\"\/><\/div><div class=\"collapsible-content\"><p class=\"font-normal\">Die wichtigste Ma\u00dfnahme ist die Aktualisierung auf 11.5.19, 12.3.10 oder 2026.1.6. Erg\u00e4nzend sollte der Import-Endpunkt f\u00fcr Klassendefinitionen auf vertrauensw\u00fcrdige Nutzer beschr\u00e4nkt und der Patchstatus aller Instanzen \u2014 einschlie\u00dflich \u00fcber Packagist eingebundener \u2014 gepr\u00fcft werden.<\/p><\/div><\/div><\/div><\/div>\n\n\n\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"@id\":\"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/#faq\",\"url\":\"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/\"},\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"Was ist CVE-2026-55634?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-55634 ist eine kritische Schwachstelle (CVSS v3.1: 9.9) im Import-Endpunkt f\u00fcr Klassendefinitionen von Pimcore. Ein authentifizierter Nutzer mit der Berechtigung objects kann PHP-Syntax in erzeugte DataObject-Klassendateien einschleusen, die beim Instanziieren der Klasse ausgef\u00fchrt wird.\"}},{\"@type\":\"Question\",\"name\":\"Welche Pimcore-Versionen sind von CVE-2026-55634 und CVE-2026-55220 betroffen?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Betroffen sind alle Pimcore-Installationen vor den Versionen 11.5.19, 12.3.10 und 2026.1.6. Beide Schwachstellen sind in diesen Versionen behoben.\"}},{\"@type\":\"Question\",\"name\":\"Wie sch\u00fctze ich meine Pimcore-Installation?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Die wichtigste Ma\u00dfnahme ist die Aktualisierung auf 11.5.19, 12.3.10 oder 2026.1.6. Erg\u00e4nzend sollte der Import-Endpunkt f\u00fcr Klassendefinitionen auf vertrauensw\u00fcrdige Nutzer beschr\u00e4nkt und der Patchstatus aller Instanzen \u2014 einschlie\u00dflich \u00fcber Packagist eingebundener \u2014 gepr\u00fcft werden.\"}}]}<\/script>\n\n\n<p class=\"lr-legal-note\" style=\"margin:32px 0 0;padding-top:16px;border-top:1px solid #e5e7eb;font-size:13px;line-height:1.55;color:#8b93a7;font-style:italic;\">Stand: 29.08.2026. Dieser Beitrag dient allgemeinen Informationszwecken und ist keine Rechts-, Sicherheits- oder Handlungsberatung im Einzelfall. Sicherheitslage und Patch-Verf\u00fcgbarkeit k\u00f6nnen sich seit der Ver\u00f6ffentlichung ge\u00e4ndert haben; ma\u00dfgeblich ist stets das verlinkte Hersteller-Advisory. Trotz sorgf\u00e4ltiger Recherche \u00fcbernehmen wir keine Gew\u00e4hr f\u00fcr Aktualit\u00e4t, Richtigkeit und Vollst\u00e4ndigkeit.<\/p>\n\n\n<div id=\"cve-check\" style=\"scroll-margin-top:100px\"><\/div>\n\n\n\n\t<div class=\"wp-block-lr-cve-quick-check lr-cveqc\">\n\t\t<div class=\"lr-cveqc-inner\">\n\n\t\t\t<div class=\"lr-cveqc-story\">\n\t\t\t\t<h2 class=\"lr-cveqc-headline\">CVE Quick Check<\/h2>\n\t\t\t\t<p class=\"lr-cveqc-text\">Pr\u00fcfen Sie in wenigen Minuten, ob zu einer aktuellen CVE Hinweise auf Ihrer extern sichtbaren Angriffsfl\u00e4che erkennbar sind.<\/p>\n\n\t\t\t\t<ul class=\"lr-cveqc-bullets\">\n\t\t\t\t\t<li><svg viewBox=\"0 0 26 26\" fill=\"none\" aria-hidden=\"true\"><circle cx=\"13\" cy=\"13\" r=\"12\" stroke=\"#00051d\" stroke-width=\"1.6\"\/><path d=\"M7.5 13.4l3.7 3.6L18.5 9\" stroke=\"#00051d\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/><\/svg><span>Grobe Einsch\u00e4tzung in wenigen Minuten per E-Mail.<\/span><\/li>\t\t\t\t\t<li><svg viewBox=\"0 0 26 26\" fill=\"none\" aria-hidden=\"true\"><circle cx=\"13\" cy=\"13\" r=\"12\" stroke=\"#00051d\" stroke-width=\"1.6\"\/><path d=\"M7.5 13.4l3.7 3.6L18.5 9\" stroke=\"#00051d\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/><\/svg><span>Details im kostenlosen Gespr\u00e4ch mit einem LocateRisk Consultant.<\/span><\/li>\t\t\t\t<\/ul>\n\n\t\t\t\t\t\t\t\t<div class=\"lr-cveqc-teaser\" aria-hidden=\"true\">\n\t\t\t\t\t<h4>Das erhalten Sie per E-Mail<\/h4>\n\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Unternehmen<\/span><span class=\"v\">Ihre Firma GmbH<\/span><\/div>\n\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Gepr\u00fcfte CVE<\/span><span class=\"v\">CVE-2024-3094<\/span><\/div>\n\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Passive Bewertung<\/span><span class=\"lr-cveqc-lamp\"><i class=\"r\"><\/i><i class=\"y\"><\/i><i class=\"g\"><\/i><\/span><\/div>\n\t\t\t\t\t<div class=\"lr-cveqc-trow\"><span class=\"k\">Hinweise zur CVE<\/span><span class=\"lr-cveqc-pill\">Hinweise gefunden<\/span><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t<div class=\"lr-cveqc-form-col\">\n\t\t\t\t<form id=\"lr-cveqc-1\" class=\"lr-cveqc-form\" method=\"post\" novalidate\n\t\t\t\t\tdata-ajax-url=\"https:\/\/locaterisk.com\/wp-admin\/admin-ajax.php\">\n\n\t\t\t\t\t<input type=\"text\" name=\"cveId\" required maxlength=\"40\"\n\t\t\t\t\t\tpattern=\"^[Cc][Vv][Ee]-\\d{4}-\\d{4,7}$\"\n\t\t\t\t\t\tvalue=\"CVE-2026-55634\"\n\t\t\t\t\t\tplaceholder=\"CVE-ID, z. B. CVE-2024-3094\" \/>\n\n\t\t\t\t\t<input type=\"email\" name=\"email\" required maxlength=\"320\"\n\t\t\t\t\t\tplaceholder=\"Gesch\u00e4ftliche E-Mail-Adresse\" \/>\n\t\t\t\t\t<p class=\"lr-cveqc-hint\">Bitte verwenden Sie Ihre gesch\u00e4ftliche E-Mail-Adresse. Die Pr\u00fcfung bezieht sich auf das Unternehmen hinter Ihrer E-Mail-Domain; Free-Mail-Adressen (z. B. Gmail) k\u00f6nnen keinem Unternehmen zugeordnet werden.<\/p>\n\n\t\t\t\t\t<!-- Optionale Telefonnummer: nur wer sie angibt, willigt laut Consent-Text\n\t\t\t\t\t     auch in eine telefonische Rueckmeldung ein. autocomplete=\"tel\" ist\n\t\t\t\t\t     gewollt (echtes Feld, kein Honeypot). -->\n\t\t\t\t\t<input type=\"tel\" name=\"phone\" maxlength=\"64\" autocomplete=\"tel\"\n\t\t\t\t\t\tplaceholder=\"Telefon (optional)\" \/>\n\t\t\t\t\t<p class=\"lr-cveqc-hint\">Nur n\u00f6tig, wenn Sie eine kurze telefonische Einordnung m\u00f6chten.<\/p>\n\n\t\t\t\t\t<!-- Honeypot: f\u00fcr Menschen unsichtbar, Bots f\u00fcllen es aus.\n\t\t\t\t\t     Neutraler Feldname (NICHT \"website\"\/\"url\"\/\"email\"), sonst f\u00fcllen\n\t\t\t\t\t     Passwort-Manager und Browser-Autofill das Feld beim echten Nutzer\n\t\t\t\t\t     und blocken ihn faelschlich. -->\n\t\t\t\t\t<div class=\"lr-cveqc-hp\" aria-hidden=\"true\">\n\t\t\t\t\t\t<label>Dieses Feld bitte leer lassen\n\t\t\t\t\t\t\t<input type=\"text\" name=\"lr_hp_check\" tabindex=\"-1\" autocomplete=\"off\" \/>\n\t\t\t\t\t\t<\/label>\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<label class=\"lr-cveqc-check\">\n\t\t\t\t\t\t<input type=\"checkbox\" name=\"consentProcessingAccepted\" value=\"1\" required \/>\n\t\t\t\t\t\t<span>Ich stimme zu, dass LocateRisk meine Angaben verarbeitet, um den Quick Check durchzuf\u00fchren, mir das Ergebnis per E-Mail zuzusenden und sich per E-Mail dazu bei mir zur\u00fcckzumelden (R\u00fcckfragen, Einordnung der Ergebnisse, Angebot eines kostenlosen Beratungstermins). Hinweise in der <a href=\"\/datenschutz\/\" target=\"_blank\" rel=\"noopener\">Datenschutzerkl\u00e4rung<\/a>.<\/span>\n\t\t\t\t\t<\/label>\n\n\t\t\t\t\t<label class=\"lr-cveqc-check\">\n\t\t\t\t\t\t<input type=\"checkbox\" name=\"marketingOptIn\" value=\"1\" \/>\n\t\t\t\t\t\t<span>Ich m\u00f6chte dar\u00fcber hinaus allgemeine Informationen zu LocateRisk Produkten, Angeboten und Security-Themen per E-Mail erhalten. Diese Einwilligung kann ich jederzeit mit Wirkung f\u00fcr die Zukunft widerrufen (optional).<\/span>\n\t\t\t\t\t<\/label>\n\n\t\t\t\t\t<input type=\"hidden\" name=\"locale\" value=\"en\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"blogPostUrl\" value=\"https:\/\/locaterisk.com\/en\/pimcore-cve-2026-55634\/\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"utmSource\" value=\"\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"utmCampaign\" value=\"\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"invalidCveMessage\" value=\"Bitte geben Sie eine g\u00fcltige CVE-ID an (z. B. CVE-2024-3094).\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"consentRequiredMessage\" value=\"Bitte stimmen Sie der Verarbeitung zu, damit wir den Quick Check durchf\u00fchren k\u00f6nnen.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"captchaMessage\" value=\"Bitte best\u00e4tigen Sie das reCAPTCHA und versuchen Sie es erneut.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"successMessage\" value=\"Vielen Dank! Bitte best\u00e4tigen Sie Ihre E-Mail-Adresse \u00fcber den Link, den wir Ihnen soeben geschickt haben. Danach starten wir den Quick Check.\" \/>\n\t\t\t\t\t<input type=\"hidden\" name=\"errorMessage\" value=\"Das hat leider nicht geklappt. Bitte pr\u00fcfen Sie Ihre Angaben und versuchen Sie es erneut.\" \/>\n\n\t\t\t\t\t\t\t\t\t\t\t<div class=\"g-recaptcha\" data-sitekey=\"6LdErNoZAAAAAD1Re2jNxtDFfcDaL9iED5MRBzjR\"\n\t\t\t\t\t\t\tdata-callback=\"verifyRecaptchaCallback\" data-expired-callback=\"expiredRecaptchaCallback\"><\/div>\n\t\t\t\t\t\t<input type=\"hidden\" name=\"g-recaptcha-response\" data-recaptcha \/>\n\t\t\t\t\t\n\t\t\t\t\t<p class=\"lr-cveqc-message\" hidden><\/p>\n\n\t\t\t\t\t<button class=\"lr-button-link\" type=\"submit\">Quick Check starten<\/button>\n\t\t\t\t<\/form>\n\t\t\t<\/div>\n\n\t\t<\/div>\n\t<\/div>\n\n\t\t<style>\n\t\t\/* CVE Quick Check im Stil der bestehenden Anfrage-Formulare:\n\t\t   wei\u00dfer Grund, zweispaltig, graue Felder, t\u00fcrkiser Button. *\/\n\t\t.lr-cveqc {\n\t\t\tbackground: #ffffff; color: #00051d; box-sizing: border-box; padding: 64px 32px;\n\t\t\tfont-family: Roboto, -apple-system, BlinkMacSystemFont, \"Segoe UI\", Helvetica, Arial, sans-serif;\n\t\t}\n\t\t.lr-cveqc * { box-sizing: border-box; }\n\t\t.lr-cveqc-inner {\n\t\t\tmax-width: 1160px; margin: 0 auto;\n\t\t\tdisplay: flex; flex-direction: row; gap: 6%; align-items: flex-start;\n\t\t}\n\t\t.lr-cveqc-story { flex: 1 1 54%; min-width: 0; }\n\t\t.lr-cveqc-form-col { flex: 0 0 38%; max-width: 420px; }\n\n\t\t.lr-cveqc-headline { color: #26d9c3; margin: 0 0 20px; }\n\t\t.lr-cveqc-text { font-size: 16px; line-height: 1.62; color: #00051d; margin: 0 0 28px; max-width: 46ch; }\n\n\t\t.lr-cveqc-bullets { list-style: none; margin: 0 0 30px; padding: 0; display: flex; flex-direction: column; gap: 16px; }\n\t\t.lr-cveqc-bullets li { display: flex; gap: 13px; align-items: flex-start; }\n\t\t.lr-cveqc-bullets svg { flex: none; width: 25px; height: 25px; margin-top: 1px; }\n\t\t.lr-cveqc-bullets span { font-size: 15px; line-height: 1.5; color: #00051d; }\n\n\t\t.lr-cveqc-teaser { border: 1px solid #e2e8e6; border-radius: 12px; padding: 18px 20px; background: linear-gradient(180deg,#fbfdfc,#f2f8f6); max-width: 430px; }\n\t\t.lr-cveqc-teaser h4 { margin: 0 0 6px; font-size: 11px; letter-spacing: .15em; text-transform: uppercase; color: #58616f; font-family: inherit; font-weight: 700; }\n\t\t.lr-cveqc-trow { display: flex; align-items: center; justify-content: space-between; gap: 10px; padding: 7px 0; font-size: 13.5px; }\n\t\t.lr-cveqc-trow + .lr-cveqc-trow { border-top: 1px dashed #dbe4e1; }\n\t\t.lr-cveqc-trow .k { color: #58616f; }\n\t\t.lr-cveqc-trow .v { font-weight: 600; color: #00051d; }\n\t\t.lr-cveqc-lamp { display: inline-flex; gap: 6px; align-items: center; }\n\t\t.lr-cveqc-lamp i { width: 13px; height: 13px; border-radius: 50%; opacity: .28; display: inline-block; }\n\t\t.lr-cveqc-lamp i.r { background: #f6105f; }\n\t\t.lr-cveqc-lamp i.y { background: #f6bf28; }\n\t\t.lr-cveqc-lamp i.g { background: #23c39a; opacity: 1; box-shadow: 0 0 0 3px rgba(35,195,154,.22); }\n\t\t.lr-cveqc-pill { font-size: 12px; font-weight: 700; padding: 3px 10px; border-radius: 999px; background: #ffe1ea; color: #c1114b; white-space: nowrap; }\n\n\t\t.lr-cveqc-form input[type=text], .lr-cveqc-form input[type=email], .lr-cveqc-form input[type=tel] {\n\t\t\tdisplay: block; width: 100%; height: 50px; margin: 0 0 10px;\n\t\t\tborder: 0; border-radius: 0; background: #dedede; color: #00051d;\n\t\t\tfont-size: 16px; padding: 0 18px; font-family: inherit;\n\t\t}\n\t\t.lr-cveqc-form input::placeholder { color: #6d7580; }\n\t\t.lr-cveqc-form input.lr-invalid { border-bottom: 2px solid #f6105f; }\n\t\t.lr-cveqc-hint { font-size: 12.5px; line-height: 1.5; color: #58616f; margin: 2px 0 16px; }\n\t\t.lr-cveqc-hp { position: absolute !important; left: -9999px !important; height: 0; overflow: hidden; }\n\t\t.lr-cveqc-check { display: flex; gap: 12px; align-items: flex-start; margin: 0 0 12px; font-size: 12.5px; line-height: 1.5; color: #00051d; }\n\t\t.lr-cveqc-check span { color: #00051d; }\n\t\t.lr-cveqc-check input { margin-top: 2px; flex: none; width: 18px; height: 18px; accent-color: #26d9c3; }\n\t\t.lr-cveqc-check a { color: inherit; text-decoration: underline; }\n\t\t.lr-cveqc .g-recaptcha { margin: 8px 0 16px; }\n\t\t.lr-cveqc-message { font-size: 14px; padding: 12px 14px; border-radius: 6px; margin: 0 0 12px; }\n\t\t.lr-cveqc-message.lr-success { background: #e2f7ef; color: #0c6b4d; }\n\t\t.lr-cveqc-message.lr-error { background: #fdeaee; color: #9b0e3f; }\n\t\t.lr-cveqc .lr-button-link, .lr-cveqc button[type=submit] {\n\t\t\tdisplay: flex; align-items: center; justify-content: center;\n\t\t\twidth: 100%; height: 50px; padding: 0 20px; box-sizing: border-box;\n\t\t\tborder: 0; cursor: pointer;\n\t\t\tbackground: #26d9c3; color: #00051d; font-weight: 700; font-size: 14px;\n\t\t\tfont-family: inherit; text-align: center; line-height: 1.2; text-decoration: none;\n\t\t\ttransition: background .15s ease;\n\t\t}\n\t\t.lr-cveqc button[type=submit]:hover { background: #0fb5a2; }\n\t\t.lr-cveqc button[disabled] { opacity: .6; cursor: default; }\n\n\t\t@media (max-width: 820px) {\n\t\t\t.lr-cveqc { padding: 40px 22px; }\n\t\t\t.lr-cveqc-inner { flex-direction: column; gap: 34px; }\n\t\t\t.lr-cveqc-story, .lr-cveqc-form-col { flex-basis: auto; max-width: 520px; width: 100%; }\n\t\t}\n\t<\/style>\n\t<script>\n\t(function () {\n\t\t\/\/ Token-Callbacks f\u00fcrs globale reCAPTCHA (identisch zum Theme, defensiv)\n\t\tif (!window.verifyRecaptchaCallback) {\n\t\t\twindow.verifyRecaptchaCallback = function (response) {\n\t\t\t\tdocument.querySelectorAll('input[data-recaptcha]').forEach(function (el) { el.value = response })\n\t\t\t}\n\t\t}\n\t\tif (!window.expiredRecaptchaCallback) {\n\t\t\twindow.expiredRecaptchaCallback = function () {\n\t\t\t\tdocument.querySelectorAll('input[data-recaptcha]').forEach(function (el) { el.value = '' })\n\t\t\t}\n\t\t}\n\n\t\tfunction showMessage(form, text, isSuccess) {\n\t\t\tvar box = form.querySelector('.lr-cveqc-message')\n\t\t\tbox.textContent = text\n\t\t\tbox.classList.remove('lr-success', 'lr-error')\n\t\t\tbox.classList.add(isSuccess ? 'lr-success' : 'lr-error')\n\t\t\tbox.hidden = false\n\t\t}\n\n\t\tfunction init() {\n\t\t\tdocument.querySelectorAll('.lr-cveqc-form').forEach(function (form) {\n\t\t\t\tform.addEventListener('submit', function (e) {\n\t\t\t\t\te.preventDefault()\n\n\t\t\t\t\tvar cve = form.querySelector('input[name=cveId]')\n\t\t\t\t\tvar email = form.querySelector('input[name=email]')\n\t\t\t\t\tvar consent = form.querySelector('input[name=consentProcessingAccepted]')\n\t\t\t\t\tvar cvePattern = \/^CVE-\\d{4}-\\d{4,7}$\/i\n\n\t\t\t\t\tcve.classList.toggle('lr-invalid', !cvePattern.test(cve.value.trim()))\n\t\t\t\t\temail.classList.toggle('lr-invalid', !email.checkValidity())\n\n\t\t\t\t\tif (!cvePattern.test(cve.value.trim())) {\n\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=invalidCveMessage]').value, false)\n\t\t\t\t\t\treturn\n\t\t\t\t\t}\n\t\t\t\t\tif (!email.checkValidity()) {\n\t\t\t\t\t\temail.reportValidity()\n\t\t\t\t\t\treturn\n\t\t\t\t\t}\n\t\t\t\t\tif (!consent.checked) {\n\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=consentRequiredMessage]').value, false)\n\t\t\t\t\t\treturn\n\t\t\t\t\t}\n\n\t\t\t\t\tvar button = form.querySelector('button[type=submit]')\n\t\t\t\t\tbutton.disabled = true\n\n\t\t\t\t\tvar data = new FormData(form)\n\t\t\t\t\tdata.append('action', 'lr_cve_quick_check')\n\n\t\t\t\t\tfetch(form.getAttribute('data-ajax-url'), { method: 'POST', body: data })\n\t\t\t\t\t\t.then(function (res) { return res.json() })\n\t\t\t\t\t\t.then(function (json) {\n\t\t\t\t\t\t\tif (json && json.success) {\n\t\t\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=successMessage]').value, true)\n\t\t\t\t\t\t\t\tform.querySelectorAll('input, button').forEach(function (el) { el.disabled = true })\n\t\t\t\t\t\t\t} else {\n\t\t\t\t\t\t\t\t\/\/ Interne Codes nie roh anzeigen, nur bekannte Codes auf\n\t\t\t\t\t\t\t\t\/\/ konfigurierte Texte mappen, sonst generische Fehlermeldung\n\t\t\t\t\t\t\t\tvar code = json && json.data && (json.data.code || json.data.message)\n\t\t\t\t\t\t\t\tvar msg = form.querySelector('input[name=errorMessage]').value\n\t\t\t\t\t\t\t\tif (code === 'invalid_cve' || code === 'invalid') {\n\t\t\t\t\t\t\t\t\tmsg = form.querySelector('input[name=invalidCveMessage]').value\n\t\t\t\t\t\t\t\t} else if (code === 'captcha') {\n\t\t\t\t\t\t\t\t\tmsg = form.querySelector('input[name=captchaMessage]').value\n\t\t\t\t\t\t\t\t}\n\t\t\t\t\t\t\t\tshowMessage(form, msg, false)\n\t\t\t\t\t\t\t\tbutton.disabled = false\n\t\t\t\t\t\t\t\tif (window.grecaptcha && form.querySelector('.g-recaptcha')) {\n\t\t\t\t\t\t\t\t\ttry { window.grecaptcha.reset() } catch (err) { \/* noop *\/ }\n\t\t\t\t\t\t\t\t}\n\t\t\t\t\t\t\t}\n\t\t\t\t\t\t})\n\t\t\t\t\t\t.catch(function () {\n\t\t\t\t\t\t\tshowMessage(form, form.querySelector('input[name=errorMessage]').value, false)\n\t\t\t\t\t\t\tbutton.disabled = false\n\t\t\t\t\t\t})\n\t\t\t\t})\n\t\t\t})\n\t\t}\n\n\t\tif (document.readyState === 'loading') {\n\t\t\tdocument.addEventListener('DOMContentLoaded', init)\n\t\t} else {\n\t\t\tinit()\n\t\t}\n\t})()\n\t<\/script>\n\t\n\n\n\n<hr class=\"wp-block-separator has-css-opacity is-style-wide\"\/>\n\n\n\n<div class=\"wp-block-lr-contact-module\"><div class=\"content\"><h2>Mehr erfahren, Demo buchen oder einfach mal kurz austauschen? Wir freuen uns!<\/h2><div class=\"contact-info-row\"><div class=\"contact-person-info\"><div class=\"avatar\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2025\/06\/Lukas_Baumann_LocateRisk-300.png\"><\/div><p><span class=\"text before\">Ihr Ansprechpartner<\/span><span class=\"bold name\"><strong>Lukas<\/strong><\/span> <span class=\"lastname\"><strong>Baumann<strong><\/strong><\/strong><\/span><strong><strong><span class=\"separator\"><\/span><span class=\"role\">CEO<\/span><\/strong><\/strong><\/p><\/div><p class=\"bold phone\"><strong><strong>+49 6151 6290246<\/strong><\/strong><\/p><strong><strong><a class=\"pr-1\" href=\"mailto:%20sales@locaterisk.com\">Jetzt Kontakt aufnehmen<\/a><\/strong><\/strong><\/div><\/div><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<div class=\"wp-block-lr-footer-module lr-footer-block\"><div class=\"content\"><div class=\"column0\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/plugins\/locate-risk-prod\/lr-blocks\/assets\/img\/lr-logo.svg\"\/><\/div><div class=\"categories\"><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/\">Home<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/blog\/\">Blog<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/know\/\">Wissen<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/about\/\">\u00dcber uns<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/contact\/\">Kontakt<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/legal-notice\/\">Impressum<\/a><\/div><div class=\"categories-break\"><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/privacy-policy\/\">Datenschutz<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/files\/agb.pdf\">AGB<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/locaterisk.com\/en\/jobs\/\">Jobs<\/a><\/div><div class=\"categories-element\"><a class=\"pr-4\" href=\"https:\/\/app.secfix.com\/trust\/locaterisk\/d1e7d433b33643aea1880bfbfeab9f60\">Trust Center<\/a><\/div><\/div><div class=\"social\"><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/locaterisk\/\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/10\/gruppe-230@3x.png\"\/><\/a><\/div><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/www.instagram.com\/locaterisk\/\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Instagram.png\"\/><\/a><\/div><div class=\"social-element\"><a target=\"_blank\" href=\"https:\/\/twitter.com\/locaterisk\"><img decoding=\"async\" src=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/twitter.png\"\/><\/a><\/div><\/div><div class=\"description\"><h6>\u00a9 LocateRisk 2026<\/h6><\/div><\/div><\/div>\n\n\n\n<style id=\"lr-ol-fix\">body>div>ol,.entry-content>div>ol{max-width:843px;margin:0 auto;padding:20px 0;font-family:Roboto;font-size:1.25rem;line-height:1.67;color:#ffffff}.blog-post ol.wp-block-list{padding-left:3rem}<\/style>\n","protected":false},"excerpt":{"rendered":"<p>CVE-2026-55634 and CVE-2026-55220 affect Pimcore. Fixes are available for three version series.<\/p>","protected":false},"author":13,"featured_media":9138,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[632],"tags":[868,865,864,866,867,87],"lr_blog_topic":[837],"class_list":["post-99109","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-news","tag-code-injection-2","tag-cve-2026-55220","tag-cve-2026-55634","tag-php-deserialisierung","tag-pimcore","tag-schwachstellenmanagement","lr_blog_topic-schwachstellen-advisories"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.2 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CVE-2026-55634: Kritische Pimcore-Schwachstelle<\/title>\n<meta name=\"description\" content=\"CVE-2026-55634 und CVE-2026-55220 betreffen Pimcore. Fehlerbereinigungen sind f\u00fcr drei Versionsreihen verf\u00fcgbar.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/locaterisk.com\/en\/pimcore-cve-2026-55634\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2026-55634: Kritische Pimcore-Schwachstelle\" \/>\n<meta property=\"og:description\" content=\"CVE-2026-55634 und CVE-2026-55220 betreffen Pimcore. Fehlerbereinigungen sind f\u00fcr drei Versionsreihen verf\u00fcgbar.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/locaterisk.com\/en\/pimcore-cve-2026-55634\/\" \/>\n<meta property=\"og:site_name\" content=\"LocateRisk\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-28T22:00:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Kristina Hoinkis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kristina Hoinkis\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/\"},\"author\":{\"name\":\"Kristina Hoinkis\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/person\\\/68f3857c15afa8ff59c545848dddcc32\"},\"headline\":\"CVE-2026-55634 und CVE-2026-55220: Kritische Pimcore-Schwachstellen\",\"datePublished\":\"2026-08-28T22:00:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/\"},\"wordCount\":22,\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"keywords\":[\"Code-Injection\",\"CVE-2026-55220\",\"CVE-2026-55634\",\"PHP-Deserialisierung\",\"Pimcore\",\"Schwachstellenmanagement\"],\"articleSection\":[\"Cybersecurity News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/\",\"name\":\"CVE-2026-55634: Kritische Pimcore-Schwachstelle\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"datePublished\":\"2026-08-28T22:00:33+00:00\",\"description\":\"CVE-2026-55634 und CVE-2026-55220 betreffen Pimcore. Fehlerbereinigungen sind f\u00fcr drei Versionsreihen verf\u00fcgbar.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/#primaryimage\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/vulnerability-disclosure.png\",\"width\":400,\"height\":400,\"caption\":\"vulnerability-disclosure\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/pimcore-cve-2026-55634\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/locaterisk.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2026-55634 und CVE-2026-55220: Kritische Pimcore-Schwachstellen\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#website\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"name\":\"LocateRisk\",\"description\":\"IT-Sicherheit messen und vergleichen\",\"publisher\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#organization\",\"name\":\"LocateRisk\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"contentUrl\":\"https:\\\/\\\/locaterisk.com\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/Kettenglieder_V0216-9.jpg\",\"width\":1920,\"height\":1080,\"caption\":\"LocateRisk\"},\"image\":{\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/locaterisk\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/locaterisk.com\\\/de\\\/#\\\/schema\\\/person\\\/68f3857c15afa8ff59c545848dddcc32\",\"name\":\"Kristina Hoinkis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g\",\"caption\":\"Kristina Hoinkis\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CVE-2026-55634: Critical Pimcore Vulnerability","description":"CVE-2026-55634 and CVE-2026-55220 affect Pimcore. Fixes are available for three version series.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/locaterisk.com\/en\/pimcore-cve-2026-55634\/","og_locale":"en_US","og_type":"article","og_title":"CVE-2026-55634: Kritische Pimcore-Schwachstelle","og_description":"CVE-2026-55634 und CVE-2026-55220 betreffen Pimcore. Fehlerbereinigungen sind f\u00fcr drei Versionsreihen verf\u00fcgbar.","og_url":"https:\/\/locaterisk.com\/en\/pimcore-cve-2026-55634\/","og_site_name":"LocateRisk","article_published_time":"2026-08-28T22:00:33+00:00","og_image":[{"width":400,"height":400,"url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","type":"image\/png"}],"author":"Kristina Hoinkis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Kristina Hoinkis"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/#article","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/"},"author":{"name":"Kristina Hoinkis","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/person\/68f3857c15afa8ff59c545848dddcc32"},"headline":"CVE-2026-55634 und CVE-2026-55220: Kritische Pimcore-Schwachstellen","datePublished":"2026-08-28T22:00:33+00:00","mainEntityOfPage":{"@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/"},"wordCount":22,"publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"image":{"@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/#primaryimage"},"thumbnailUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","keywords":["Code-Injection","CVE-2026-55220","CVE-2026-55634","PHP-Deserialisierung","Pimcore","Schwachstellenmanagement"],"articleSection":["Cybersecurity News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/","url":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/","name":"CVE-2026-55634: Critical Pimcore Vulnerability","isPartOf":{"@id":"https:\/\/locaterisk.com\/de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/#primaryimage"},"image":{"@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/#primaryimage"},"thumbnailUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","datePublished":"2026-08-28T22:00:33+00:00","description":"CVE-2026-55634 and CVE-2026-55220 affect Pimcore. Fixes are available for three version series.","breadcrumb":{"@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/#primaryimage","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2026\/07\/vulnerability-disclosure.png","width":400,"height":400,"caption":"vulnerability-disclosure"},{"@type":"BreadcrumbList","@id":"https:\/\/locaterisk.com\/de\/pimcore-cve-2026-55634\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/locaterisk.com\/"},{"@type":"ListItem","position":2,"name":"CVE-2026-55634 und CVE-2026-55220: Kritische Pimcore-Schwachstellen"}]},{"@type":"WebSite","@id":"https:\/\/locaterisk.com\/de\/#website","url":"https:\/\/locaterisk.com\/de\/","name":"LocateRisk","description":"Measure and compare IT security","publisher":{"@id":"https:\/\/locaterisk.com\/de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/locaterisk.com\/de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/locaterisk.com\/de\/#organization","name":"LocateRisk","url":"https:\/\/locaterisk.com\/de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/","url":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","contentUrl":"https:\/\/locaterisk.com\/wp-content\/uploads\/2020\/11\/Kettenglieder_V0216-9.jpg","width":1920,"height":1080,"caption":"LocateRisk"},"image":{"@id":"https:\/\/locaterisk.com\/de\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.linkedin.com\/company\/locaterisk\/"]},{"@type":"Person","@id":"https:\/\/locaterisk.com\/de\/#\/schema\/person\/68f3857c15afa8ff59c545848dddcc32","name":"Kristina Hoinkis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7756f96249844e60ceb218f17e06217dcbed4993bcd2124e3f59bb8675324f0d?s=96&d=mm&r=g","caption":"Kristina Hoinkis"}}]}},"_links":{"self":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/99109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/comments?post=99109"}],"version-history":[{"count":1,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/99109\/revisions"}],"predecessor-version":[{"id":99110,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/posts\/99109\/revisions\/99110"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media\/9138"}],"wp:attachment":[{"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/media?parent=99109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/categories?post=99109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/tags?post=99109"},{"taxonomy":"lr_blog_topic","embeddable":true,"href":"https:\/\/locaterisk.com\/en\/wp-json\/wp\/v2\/lr_blog_topic?post=99109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}