CVE-2026-55072 | Pimcore up to 2026.1.4 ClassDefinition Block.php Block::load ClassDefinition UID input validation
A vulnerability identified as critical has been detected in Pimcore up to 2026.1.4. This vulnerability affects the function Block::load of the file models/DataObject/ClassDefinition/Data/Block.php of the component ClassDefinition. This manipulation of the argument ClassDefinition UID causes improper input validation.
This vulnerability is registered as CVE-2026-55072. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More