Code Injection in Pimcore - CVE-2026-55634
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper control of code generation in the DataObject class-definition field-name handling when importing a class definition containing a crafted field name. A remote user can import a crafted class definition to execute arbitrary code.
Execution occurs when an object of the affected class is loaded.