{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-55634","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-06-16T23:52:12.056Z","datePublished":"2026-08-28T19:16:20.078Z","dateUpdated":"2026-08-28T20:06:15.024Z"},"containers":{"cna":{"title":"Pimcore: Remote Code Execution via DataObject Class-Definition Field Name","problemTypes":[{"descriptions":[{"cweId":"CWE-89","lang":"en","description":"CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-94","lang":"en","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"name":"https://github.com/pimcore/pimcore/security/advisories/GHSA-9x44-4gxf-8c25","tags":["x_refsource_CONFIRM"],"url":"https://github.com/pimcore/pimcore/security/advisories/GHSA-9x44-4gxf-8c25"},{"name":"https://github.com/pimcore/pimcore/pull/19183","tags":["x_refsource_MISC"],"url":"https://github.com/pimcore/pimcore/pull/19183"},{"name":"https://github.com/pimcore/pimcore/commit/a4f8c3cfee58b7d5fe4873d67782eff58dae9b9d","tags":["x_refsource_MISC"],"url":"https://github.com/pimcore/pimcore/commit/a4f8c3cfee58b7d5fe4873d67782eff58dae9b9d"},{"name":"https://github.com/advisories/GHSA-r2f4-ff2p-xc64","tags":["x_refsource_MISC"],"url":"https://github.com/advisories/GHSA-r2f4-ff2p-xc64"},{"name":"https://github.com/pimcore/pimcore/releases/tag/v2026.1.6","tags":["x_refsource_MISC"],"url":"https://github.com/pimcore/pimcore/releases/tag/v2026.1.6"}],"affected":[{"vendor":"pimcore","product":"pimcore","versions":[{"version":"< 11.5.19","status":"affected"},{"version":">= 12.0.0-RC1, < 12.3.10","status":"affected"},{"version":">= 2026.1.0, < 2026.1.6","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-08-28T19:16:20.078Z"},"descriptions":[{"lang":"en","value":"Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and by models/DataObject/ClassDefinition/Helper/Dao.php into ALTER TABLE identifiers. An authenticated user with the objects permission can inject PHP syntax into the generated DataObject class, causing attacker-controlled code in generated var/classes/DataObject/.php files to run when an object of that class is instantiated, and can also inject SQL identifier content into schema-changing statements. The central models/DataObject/ClassDefinition/Data.php::setName() validation did not reject semicolons, braces, backticks, spaces, or other non-identifier characters. This issue is fixed in versions 11.5.19, 12.3.10, and 2026.1.6."}],"source":{"advisory":"GHSA-9x44-4gxf-8c25","discovery":"UNKNOWN"}},"adp":[{"references":[{"url":"https://github.com/advisories/GHSA-r2f4-ff2p-xc64","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-28T20:06:04.514009Z","id":"CVE-2026-55634","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-28T20:06:15.024Z"}}]}}