Skip to content

Pimcore

v2026.2.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

cdp cms cms-framework customer-data-platform dam data-management
+13 more
digital-platform ecommerce ecommerce-platform experience-manager master-data-management mdm online-shop pim pimcore product-information-management product-management shop wcms

Affected surfaces

rce_ssrf

Summary

AI summary

Restrict allowed classes in Site deserialization for security.

Full changelog

What's Changed

  • Refine return type of UserAwareController::getPimcoreUser() by @jdreesen in https://github.com/pimcore/pimcore/pull/18693
  • Remove unnecessary blank line in codeception.yaml by @bluvulture in https://github.com/pimcore/pimcore/pull/18829
  • Refactor v11 specific workflows to v12 by @kingjia90 in https://github.com/pimcore/pimcore/pull/19082
  • feat: add TemplateProviderInterface extension point to ControllerDataProvider by @fashxp in https://github.com/pimcore/pimcore/pull/19146
  • Delete backup workflow files by @berfinyuksel in https://github.com/pimcore/pimcore/pull/19096
  • Remove some admin functions and deprecate admin translations by @robertSt7 in https://github.com/pimcore/pimcore/pull/19131
  • [Improvement] CDN integration by @mcop1 in https://github.com/pimcore/pimcore/pull/19122
  • security: restrict allowed_classes in Site::setDomains() and setLocalizedErrorDocuments() deserialization by @XananasX7 in https://github.com/pimcore/pimcore/pull/19162
  • Revise README for improved clarity and structure by @fashxp in https://github.com/pimcore/pimcore/pull/19194
  • [Task] CDN integration -image optimizer support by @mcop1 in https://github.com/pimcore/pimcore/pull/19178
  • [User] Add theme column to user by @martineiber in https://github.com/pimcore/pimcore/pull/19214
  • Handle case where mime type is not found by @cancan101 in https://github.com/pimcore/pimcore/pull/18889
  • Ensure that dimensions are integers by @cancan101 in https://github.com/pimcore/pimcore/pull/18890
  • docs update by @fashxp in https://github.com/pimcore/pimcore/pull/19222
  • Fix deprecation from FOSJsRoutingBundle by @jdreesen in https://github.com/pimcore/pimcore/pull/18852
  • Add missing ownername condition when fetching objectbrick relations by @codata-swiss in https://github.com/pimcore/pimcore/pull/19180
  • Refactor ControllerDataProvider & allow to define templates exclusively via custom template providers by @jdreesen in https://github.com/pimcore/pimcore/pull/19147

New Contributors

  • @XananasX7 made their first contribution in https://github.com/pimcore/pimcore/pull/19162
  • @codata-swiss made their first contribution in https://github.com/pimcore/pimcore/pull/19180

Full Changelog: https://github.com/pimcore/pimcore/compare/v2026.1.6...v2026.2.1

Security Fixes

  • security: restrict allowed_classes in Site::setDomains() and setLocalizedErrorDocuments() deserialization

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Pimcore

Get notified when new releases ship.

Sign up free

About Pimcore

Multi-channel experience and engagement management platform.

All releases →

Related context

Beta — feedback welcome: [email protected]