{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apimcorestudio_backend_bundle/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pimcore:studio_backend_bundle:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-55212"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["studio-backend-bundle (\u003c 2025.4.6, 2026.1.0 - 2026.1.5)","studio-backend-bundle (\u003c 2025.4.6, \u003e= 2026.1.0 \u003c 2026.1.6)","studio-backend-bundle (\u003c 2025.4.6)","studio-backend-bundle (\u003e= 2026.1.0, \u003c 2026.1.6)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","cms","vulnerability","account-takeover","cve-2026-55207","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Pimcore"],"content_html":"\u003cp\u003ePimcore Studio API, specifically the \u003ccode\u003epimcore/studio-backend-bundle\u003c/code\u003e, contains a security flaw where the class definition creation endpoint is protected by the \u003ccode\u003eobjects\u003c/code\u003e permission rather than the intended \u003ccode\u003eclasses\u003c/code\u003e permission. This vulnerability, tracked as CVE-2026-55212, allows standard authenticated users with content editing rights to perform administrative actions.\u003c/p\u003e\n\u003cp\u003eWhen exploited, this allows unauthorized users to generate new database tables and create PHP class files on the application server. This bypasses the security controls enforced in the Classic Admin interface. Additionally, the API lacks proper input validation for the \u003ccode\u003euid\u003c/code\u003e parameter at the controller layer, which can lead to unhandled internal exceptions and potential information disclosure, such as stack traces, depending on the server's debug configuration. Affected versions are those earlier than 2025.4.6 and versions within the 2026.1.x range prior to 2026.1.6.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Pimcore application using credentials of a user account possessing only the \u003ccode\u003eobjects\u003c/code\u003e permission.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the Studio API at \u003ccode\u003ePOST /pimcore-studio/api/class/definition/configuration-view/detail/create\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application's \u003ccode\u003eCreateController\u003c/code\u003e incorrectly validates the user's authorization against the \u003ccode\u003eDATA_OBJECTS\u003c/code\u003e permission.\u003c/li\u003e\n\u003cli\u003eAttacker provides a JSON payload containing a class name and an arbitrary \u003ccode\u003euid\u003c/code\u003e value.\u003c/li\u003e\n\u003cli\u003eThe API boundary performs only a basic empty-string check, allowing malformed or unauthorized \u003ccode\u003euid\u003c/code\u003e data to proceed.\u003c/li\u003e\n\u003cli\u003eThe Pimcore model layer processes the request, creating new database tables in the backend.\u003c/li\u003e\n\u003cli\u003eThe system generates new PHP class files on the server based on the user-provided definition.\u003c/li\u003e\n\u003cli\u003eFinal objective achieved: Unauthorized schema modification and potential execution of malicious object structures.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in privilege escalation from a standard editor-level user to an administrative-level structural capability. An attacker can modify the application schema, potentially corrupting existing data models or introducing backdoored class structures. Furthermore, the lack of input validation on the \u003ccode\u003euid\u003c/code\u003e parameter can lead to server-side exceptions, potentially exposing sensitive environment details via stack traces in error responses.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Pimcore \u003ccode\u003estudio-backend-bundle\u003c/code\u003e to version 2025.4.6 or 2026.1.6 or later to address CVE-2026-55212.\u003c/li\u003e\n\u003cli\u003eAudit existing class definitions for unauthorized entries created by non-admin users.\u003c/li\u003e\n\u003cli\u003eReview web server logs for HTTP POST requests to \u003ccode\u003e/pimcore-studio/api/class/definition/configuration-view/detail/create\u003c/code\u003e originating from non-administrative user sessions.\u003c/li\u003e\n\u003cli\u003eDisable debug mode in production environments to prevent the disclosure of internal stack traces triggered by malformed API inputs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:14:44Z","date_published":"2026-08-28T21:14:22Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pimcore-privilege-escalation/","summary":"An insufficient permission check in the Pimcore studio-backend-bundle allows authenticated users with standard object-editing privileges to create class definitions, leading to unauthorized schema modification and server-side file creation.","title":"Pimcore Studio API Privilege Escalation via Class Definition Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-pimcore-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:pimcore:studio_backend_bundle:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}