CVE-2026-46722

Source
https://cve.org/CVERecord?id=CVE-2026-46722
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46722.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-46722
Aliases
Published
2026-05-19T09:23:02.618Z
Modified
2026-07-15T01:48:51.731645655Z
Severity
  • 5.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N CVSS Calculator
Summary
XML External Entity Injection in extension "Faceted Search" (ke_search)
Details

The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.

Database specific
{
    "cwe_ids": [
        "CWE-611"
    ],
    "cna_assigner": "TYPO3",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46722.json"
}
References

Affected packages

Git / github.com/tpwd/ke_search

Affected ranges

Type
GIT
Repo
https://github.com/tpwd/ke_search
Events
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.0.1"
        },
        {
            "introduced": "6.0.0"
        },
        {
            "fixed": "6.6.1"
        },
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.6.2"
        },
        {
            "introduced": "0"
        },
        {
            "fixed": "4.6.7"
        }
    ]
}

Affected versions

1.*
1.99.1
1.99.2
1.99.3
1.99.4
v1.*
v1.99.0
v1.99.4
v1.99.5
v1.99.7
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.2.0
v2.2.1
v2.4.0
v2.4.1
v2.5.0
v2.6.0
v2.6.1
v2.6.2
v2.6.3
v2.7.0
v2.8.0
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.2.0
v3.3.0
v3.3.1
v3.4.0
v3.4.1
v3.4.2
v3.5.0
v3.6.0
v3.6.1
v3.7.0
v3.7.1
v3.7.2
v3.8.0
v3.8.1
v3.9.0
v4.*
v4.0.0
v4.0.1
v4.1.0
v4.2.0
v4.3.0
v4.3.1
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.1.0
v5.1.1
v5.1.2
v5.1.3
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
v5.5.0
v5.5.1
v5.5.2
v5.5.3
v5.6.0
v5.6.1
v6.*
v6.0.0
v6.0.1
v6.1.0
v6.1.1
v6.1.2
v6.1.3
v6.2.0
v6.3.0
v6.4.0
v6.4.1
v6.5.0
v6.6.0
v7.*
v7.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46722.json"