Path Traversal Vulnerability in TYPO3's File Indexer
CVE-2026-46724

5.9MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
19 May 2026

What is CVE-2026-46724?

A path traversal vulnerability exists in TYPO3’s file indexer due to improper normalization of configured directory paths. This flaw allows backend users with permissions to edit indexer configurations to index documents from arbitrary locations on the server's filesystem, potentially leading to unauthorized access to sensitive files and data. It is imperative to restrict user access to meet security protocols and mitigate risks associated with this vulnerability.

Affected Version(s)

Extension "Faceted Search" 7.0.0 < 7.0.1

Extension "Faceted Search" 6.0.0 < 6.6.1

Extension "Faceted Search" 5.0.0 < 5.6.2

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seungbin Yang
Christian BĂĽlter
.