XML External Entity Injection Vulnerability in Exterro FTK Imager
CVE-2026-82525
6.8MEDIUM
What is CVE-2026-82525?
The Exterro FTK Imager software prior to version 8.3 features a vulnerability that permits XML external entity (XXE) injection. This flaw could enable attackers to exploit crafted Report.xml files embedded in UFDR ZIP evidence items to read sensitive files from the host filesystem. By leveraging malicious external entity references and XSLT stylesheets, an attacker can manipulate the XML parser into resolving file system paths, thus exfiltrating data through a generated image URL to an attacker-controlled endpoint. This process highlights a critical weakness in the handling of external entities within FTK Imager, posing significant risks to data integrity and security.
Affected Version(s)
FTK Imager 0
