CVE-2026-46722
Last modified
CVE-2026-46722 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-46722?
How severe is CVE-2026-46722?
How do I fix CVE-2026-46722?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-46717Nezha Monitoring is a self-hostable, lightweight, servers an…7.7
- CVE-2026-46718Use of Externally-Controlled Input to Select Classes or Code…6.5
- CVE-2026-46719Net::Statsd::Lite versions before 0.9.0 for Perl allowed met…6.5
- CVE-2026-4672GitLab has remediated an issue in GitLab CE/EE affecting all…4.3
- CVE-2026-46720Net::Statsd::Tiny versions before 0.3.8 for Perl allowed met…8.2
- CVE-2026-46721The create and edit flows do not restrict which user propert…6.9
- CVE-2026-46723The additional_tables configuration of the page and tt_conte…5.9
- CVE-2026-46724The file indexer does not normalize the configured directory…5.9
- CVE-2026-46725The extension passes an attacker-controlled cookie directly …9.2
- CVE-2026-46726Improper Input Validation, Exposure of Sensitive Information…7.5
- CVE-2026-46727An issue was discovered in Ruby 4 before 4.0.5. A race condi…8.1
- CVE-2026-46728Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signa…8.8
Are you affected by CVE-2026-46722?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
