CVE-2026-11407High· 7.2▾ TwilightPimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.6%
Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attackers to execute arbitrary methods on PHP objects by exploiting empty checkMethodAllowed() and checkPropertyAllowed() implementations in the custom Twig SecurityPolicy. Attackers can supply malicious Twig templates through the DataObject ClassDefinition Layout\Text component to perform arbitrary file reads, execute arbitrary database queries, and potentially achieve remote code execution via PHP object gadget chains, with the pimcore_* function wildcard further broadening the bypass to all Pimcore Twig functions.
pimcore/pimcore <= 12.3.8Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55220CriticalPimcore is an Open Source Data & Experience Management Platform
CVE-2026-55634Critical· 9.9Pimcore is an Open Source Data & Experience Management Platform
CVE-2026-55416High· 8.8Pimcore is an Open Source Data & Experience Management Platform
CVE-2026-55207High· 8.8Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
CVE-2026-55208High· 7.7Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
CVE-2026-55072High· 8.5Pimcore is an Open Source Data & Experience Management Platform