CVE-2026-82525 Details
Description
Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file inside a UFDR ZIP evidence item. Attackers can craft a malicious UFDR archive that, when previewed by an examiner, causes the XML parser to resolve file:// external entity references and execute msxsl:script within the external stylesheet to exfiltrate the resolved file contents to an attacker-controlled endpoint via a generated image URL.
A XML external entity (XXE) injection vulnerability has been identified in Exterro FTK Imager versions prior to 8.3. This vulnerability allows attackers to read arbitrary files from the host filesystem. Exploitation involves embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file, which is placed inside a UFDR ZIP evidence item. When the crafted UFDR archive is previewed by an examiner, the XML parser resolves file:// external entity references and executes msxsl:script within the external stylesheet. This process can exfiltrate the contents of the resolved files to an attacker-controlled endpoint via a generated image URL.
Users are advised to update to Exterro FTK Imager version 8.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 3, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
| CWE-829 | Inclusion of Functionality from Untrusted Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Exterro FTK Imager | < 8.3 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2026 | New CVE Received | [email protected] |
Volerion