Security Advisory

CVE-2026-46724

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-19 09:24:04
Last updated 2026-06-03 10:57:06
Assigner TYPO3
CVSS score 5.9
State PUBLISHED

Description

The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations on the server file system through path traversal sequences.