THREAT OPS › Threat News › [GHSA] GHSA-h854-c3m3-mh5v (high) — Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
[GHSA] GHSA-h854-c3m3-mh5v (high) — Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
GHSA-h854-c3m3-mh5v Severity: high CVE: CVE-2026-55207
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
## Summary
An unauthenticated attacker takes over any Pimcore admin account by sending a password reset request with an attacker-controlled `resetPasswordUrl`. The server generates a real cryptographic recov
Indicators of compromise
- 48d784c5bfcc09c8b897f2ab34038419md5
- CVE-2026-55207cve
- CVE-2021-39189cve
- https://ATTACKER_SERVER:9999/stealurl
Original source: https://github.com/advisories/GHSA-h854-c3m3-mh5v