Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.4%
exploitation probability
0.4%top 72% of all CVEs
observed exploitation
nono source reports it
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl. The server generates a real cryptographic recovery token, appends it to the supplied URL, and emails the link to the victim; when the victim clicks the link, the token is sent to the attacker and can be used with POST /pimcore-studio/api/login/token to authenticate with full admin privileges while bypassing two-factor authentication. This issue is fixed in versions 2025.4.6 and 2026.1.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
pimcore · pimcoreReferences
https://github.com/pimcore/pimcore/security/advisories/GHSA-h854-c3m3-mh5vhttps://github.com/pimcore/studio-backend-bundle/commit/ea9d329686f5e5aea2eec378d63ac2deb965bb27https://github.com/pimcore/studio-backend-bundle/pull/1882https://github.com/pimcore/studio-backend-bundle/releases/tag/v2025.4.6https://github.com/pimcore/studio-backend-bundle/releases/tag/v2026.1.6