The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.
CVSS
No CVSS.
References
Configurations
No configuration.
History
19 May 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-19 10:16
Updated : 2026-05-19 14:47
NVD link : CVE-2026-46722
Mitre link : CVE-2026-46722
CVE.ORG link : CVE-2026-46722
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference
