Impact
An unauthenticated attacker who knows a valid admin username can coerce the application into generating a legitimate recovery token, then append this token to an attacker‑controlled link. The victim’s click forwards the token to the attacker, who can then use it to authenticate with full administrative privileges via the token‑based login API, thereby bypassing two‑factor authentication. The vulnerability, identified as a CWE‑640 (Identity Management and Authentication Failures), effectively allows an attacker to obtain unlimited control over any admin account.
Affected Systems
The flaw affects the Pimcore platform, specifically all releases prior to versions 2025.4.6 and 2026.1.6. All installations running older builds of the Pimcore Data & Experience Management Platform are at risk.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score of < 1% indicates a very low probability of public exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack path—sending a password‑reset request with a crafted URL and waiting for the victim to click—can be automated or social‑engineered. Based on the description, it is inferred that if the victim follows the injected link, the attacker can achieve full administrative takeover by submitting the recovered token.
OpenCVE Enrichment