CVE-2026-46722
XML External Entity Injection in extension "Faceted Search" (ke_search)
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
19 May 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Affected products
TYPO3 · Extension "Faceted Search"Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →