CRITICAL 9.9 CVE-2026-55634 Published 28 Aug 2026

Pimcore Data Object Injection Vulnerability

Worried this affects one of your servers?

Pimcore, an open-source Data & Experience Management Platform, was affected by an authentication bypass and code injection vulnerability.

Prior to versions 11.5.19, 12.3.10, and 2026.1.6, an authenticated user could inject PHP syntax and SQL identifiers into DataObject class definitions, leading to attacker-controlled code execution and schema changes.

This issue is fixed in the mentioned versions.

Reference: CVE-2026-55634 on NVD

← Back to Security News