CVE-2026-46724

The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations on the server file system through path traversal sequences.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-05-19 10:16

Updated : 2026-06-17 10:53


NVD link : CVE-2026-46724

Mitre link : CVE-2026-46724

CVE.ORG link : CVE-2026-46724


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')