External Entity Resolution Vulnerability in TYPO3 File Indexer
CVE-2026-46722

5.9MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
19 May 2026

What is CVE-2026-46722?

A security flaw in TYPO3's OOXML parsing allows for external entity resolution, potentially exposing sensitive local files or enabling outbound HTTP requests. Maliciously crafted xlsx or pptx documents can trigger these actions when placed in an indexed directory, leading to unauthorized content retrieval that may be added to the search index.

Affected Version(s)

Extension "Faceted Search" 7.0.0 < 7.0.1

Extension "Faceted Search" 6.0.0 < 6.6.1

Extension "Faceted Search" 5.0.0 < 5.6.2

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seungbin Yang
Christian BĂĽlter
.