THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h854-c3m3-mh5v (high) — Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

[GHSA] GHSA-h854-c3m3-mh5v (high) — Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

highgithub_advisoriesPublished 2026-08-28

GHSA-h854-c3m3-mh5v Severity: high CVE: CVE-2026-55207

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

## Summary

An unauthenticated attacker takes over any Pimcore admin account by sending a password reset request with an attacker-controlled `resetPasswordUrl`. The server generates a real cryptographic recov

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h854-c3m3-mh5v