CVE-2026-46722 Details
Description
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.
A vulnerability in the TYPO3 extension 'Faceted Search' (ke_search) allows for XML External Entity (XXE) injection. The issue arises because the OOXML parser in the file indexer does not disable external entity resolution. This flaw enables a crafted xlsx or pptx document placed in an indexed directory to read local files or make outbound HTTP requests, with the retrieved content being added to the search index. Additionally, the file indexer's directory path normalization is inadequate, permitting path traversal exploitation to access arbitrary server files.
Users are advised to update to version 7.0.1, 6.6.1, or 5.6.2, available through the TYPO3 Extension Manager, Packagist, or directly from the TYPO3 Extensions Repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2026CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-011 | TYPO3 | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | TYPO3 |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 Faceted Search | 7.0.0 (semver) 6.0.0 - 6.6.0 <= 5.6.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TYPO3 |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | TYPO3 |
Volerion