Security Advisory

CVE-2026-46723

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-19 09:23:32
Last updated 2026-05-19 13:30:30
Assigner TYPO3
CVSS score 5.9
State PUBLISHED

Description

The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.