PatchSiren cyber security CVE debrief
CVE-2026-46722 TYPO3 CVE debrief
A medium-severity XML External Entity (XXE) vulnerability in the OOXML file indexer allows crafted .xlsx or .pptx documents to trigger local file disclosure or outbound HTTP requests, with retrieved content written to the search index. The vulnerability was published on 2026-05-19 and affects TYPO3 CMS based on the vendor security advisory reference. The CVSS 4.0 vector indicates network attack vector with low attack complexity, privileged access required, and high confidentiality impact on the vulnerable component. The underlying weakness is CWE-611 (Improper Restriction of XML External Entity Reference).
- Vendor
- TYPO3
- Product
- Extension "Faceted Search"
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-19
- Original CVE updated
- 2026-05-19
- Advisory published
- 2026-05-19
- Advisory updated
- 2026-05-19
Who should care
TYPO3 CMS administrators, security teams managing document indexing pipelines, and organizations using file indexers that process OOXML documents
Technical summary
The vulnerability exists in the OOXML parsing component of a file indexer, which fails to disable external entity resolution when processing Microsoft Office Open XML format documents (.xlsx, .pptx). An attacker with privileged access can place a malicious document in an indexed directory. When the indexer processes the document, the embedded external entity references resolve, causing the application to read local files or make outbound HTTP requests. The retrieved content is then written to the search index, potentially exposing sensitive information or facilitating server-side request forgery (SSRF) attacks. The CVSS 4.0 score of 5.9 (Medium) reflects the privileged access requirement and high confidentiality impact, though integrity and availability impacts are not affected.
Defensive priority
medium
Recommended defensive actions
- Review file indexer configurations to disable external entity resolution in XML parsers
- Restrict upload of .xlsx and .pptx files to trusted administrative users only
- Monitor search index content for unexpected external data
- Apply TYPO3 security advisory typo3-ext-sa-2026-011 when available
- Implement network egress controls on indexing services to prevent unauthorized outbound HTTP requests
Evidence notes
Vendor attribution to TYPO3 is based on reference domain candidate evidence with low confidence and requires review. The NVD entry shows vulnStatus 'Deferred'.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46722 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46722
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46722 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46722
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://typo3.org/security/advisory/typo3-ext-sa-2026-011
f4fb688c-4412-4426-b4b8-421ecf27b14a
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.