THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9x44-4gxf-8c25 (critical) — Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name

[GHSA] GHSA-9x44-4gxf-8c25 (critical) — Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name

medgithub_advisoriesPublished 2026-08-28

GHSA-9x44-4gxf-8c25 Severity: critical CVE: CVE-2026-55634

Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name

## Overview

A DataObject **class-definition field name** is concatenated, without an identifier allowlist, into the PHP class source that Pimcore generates for every DataObject class (`protected $<fieldName>;`). A user holding only the ordinary `objec

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9x44-4gxf-8c25