CVE-2026-46723: TYPO3 Extension Faceted Search

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.

Affected products

  • TYPO3 Extension Faceted Search: from 7.0.0, before 7.0.1 (fixed in 7.0.1); from 6.0.0, before 6.6.1 (fixed in 6.6.1); before 5.6.2 (fixed in 5.6.2)

Published 2026-05-19. Last modified 2026-06-17.