The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-011 |
|
History
Tue, 19 May 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The additional_tables configuration of the page and tt_content indexers accepts arbitrary table and field names. A backend user with permission to edit indexer configurations can copy sensitive data from internal TYPO3 tables into the search index. | |
| Title | Information Disclosure in extension "Faceted Search" (ke_search) | |
| Weaknesses | CWE-668 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-05-19T09:23:32.228Z
Reserved: 2026-05-16T09:55:27.478Z
Link: CVE-2026-46723
No data.
Status : Received
Published: 2026-05-19T10:16:25.187
Modified: 2026-05-19T10:16:25.187
Link: CVE-2026-46723
No data.
OpenCVE Enrichment
Updated: 2026-05-19T11:30:03Z
Weaknesses