CVE-2026-46722

The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP requests to be performed, with the retrieved content being written to the search index.
CVSS

No CVSS.

Configurations

No configuration.

History

19 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-19 10:16

Updated : 2026-05-19 14:47


NVD link : CVE-2026-46722

Mitre link : CVE-2026-46722

CVE.ORG link : CVE-2026-46722


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference