<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:36:32.550817+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335563</id>
    <title>EUVD-2026-335563</title>
    <updated>2026-10-02T12:36:32.580727+00:00</updated>
    <content>EUVD-2026-335563</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335563"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55207</id>
    <title>fkie_cve-2026-55207</title>
    <updated>2026-10-02T12:36:32.580757+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pimcore is an Open Source Data &amp; Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated attacker who knows a valid admin username can take over any Pimcore admin account by sending a password reset request with an attacker-controlled resetPasswordUrl. The server generates a real cryptographic recovery token, appends it to the supplied URL, and emails the link to the victim; when the victim clicks the link, the token is sent to the attacker and can be used with POST /pimcore-studio/api/login/token to authenticate with full admin privileges while bypassing two-factor authentication. This issue is fixed in versions 2025.4.6 and 2026.1.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55207"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h854-c3m3-mh5v</id>
    <title>GHSA-h854-c3m3-mh5v — Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account…</title>
    <updated>2026-10-02T12:36:32.580793+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: pimcore/studio-backend-bundle</p>
<p>## Summary</p>
<p>An unauthenticated attacker takes over any Pimcore admin account by sending a password reset request with an attacker-controlled `resetPasswordUrl`. The server generates a real cryptographic recovery token, appends it to the attacker's URL, and emails the link to the victim. When the victim clicks the link in their email, the token is sent to the attacker's server. The attacker then uses `POST /pimcore-studio/api/login/token` to authenticate as the victim with full admin privileges. Token login explicitly disables two-factor authentication, so even accounts with TOTP/Google Authenticator are compromised.</p>
<p>## Vulnerability Details</p>
<p>### Unauthenticated Endpoint Accepts Attacker URL</p>
<p>The reset password endpoint at `src/User/Controller/ResetPasswordController.php` line 53 is public (uses `PUBLIC_STUDIO_API` voter). The `ResetPassword` schema at `src/User/Schema/ResetPassword.php` accepts a `resetPasswordUrl` string as a required parameter with zero validation. No URL scheme check, no domain allowlist, no comparison against the configured system domain.</p>
<p>```php
final readonly class ResetPassword
{
    public function __construct(
        private string $username,
        private string $resetPasswordUrl  // attacker-controlled, no validation
    ) {}
}
```</p>
<p>### Token Appended to Attacker URL</p>
<p>In `src/User/Service/UserLoginService.php` at line 64-65, the service generates a real recovery token and concatenates the attacker's URL with the token:</p>
<p>```php
$token = $this-&gt;…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h854-c3m3-mh5v"/>
  </entry>
</feed>
