THREAT OPS › Threat News › [GHSA] GHSA-9x44-4gxf-8c25 (critical) — Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
[GHSA] GHSA-9x44-4gxf-8c25 (critical) — Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
GHSA-9x44-4gxf-8c25 Severity: critical CVE: CVE-2026-55634
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
## Overview
A DataObject **class-definition field name** is concatenated, without an identifier allowlist, into the PHP class source that Pimcore generates for every DataObject class (`protected $<fieldName>;`). A user holding only the ordinary `objec
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55634cve
- CVE-2026-5394cve
Original source: https://github.com/advisories/GHSA-9x44-4gxf-8c25