CVE-2026-46723 Details
Description
The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.
A vulnerability in the TYPO3 extension 'Faceted Search' (ke_search) allows backend users with permission to edit indexer configurations to index sensitive data from internal TYPO3 tables. This issue arises because the 'additional_tables' configuration of the page and tt_content indexers accepts arbitrary table and field names. Exploitation of this vulnerability could lead to unauthorized information disclosure.
Users of the 'Faceted Search' extension are advised to update to version 7.0.1, 6.6.1, or 5.6.2. These versions are available from the TYPO3 extension manager, Packagist, and the TYPO3 Extensions Repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2026CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-011 | TYPO3 | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-668 | Exposure of Resource to Wrong Sphere | TYPO3 |
Affected Products
| Product | Versions |
|---|---|
| TYPO3 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TYPO3 |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | New CVE Received | TYPO3 |
Volerion