Arbitrary Data Exposure in TYPO3 Configuration by TYPO3
CVE-2026-46723

5.9MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
19 May 2026

What is CVE-2026-46723?

A misconfiguration in the additional_tables setting for page and tt_content indexers within TYPO3 allows a backend user with sufficient permissions to manipulate indexer configurations. This could lead to the inclusion of sensitive data from internal TYPO3 tables into the search index, thus exposing sensitive information to unauthorized access.

Affected Version(s)

Extension "Faceted Search" 7.0.0 < 7.0.1

Extension "Faceted Search" 6.0.0 < 6.6.1

Extension "Faceted Search" 0 < 5.6.2

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seungbin Yang
Christian BĂĽlter
.