CVE-2026-46724: TYPO3 Extension Faceted Search

Medium severity, CVSS 5.9. EPSS: 0.5% chance of exploitation in the next 30 days.

The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations on the server file system through path traversal sequences.

Affected products

  • TYPO3 Extension Faceted Search: from 7.0.0, before 7.0.1 (fixed in 7.0.1); from 6.0.0, before 6.6.1 (fixed in 6.6.1); from 5.0.0, before 5.6.2 (fixed in 5.6.2); before 4.6.7 (fixed in 4.6.7)

Published 2026-05-19. Last modified 2026-06-17.