PT-2026-41864 · Unknown · Ps Facetedsearch

Christian Bülter

+1

·

Published

2026-05-19

·

Updated

2026-05-19

·

CVE-2026-46724

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Faceted Search (ke search) (affected versions not specified)
Description The file indexer fails to normalize the configured directory path. This allows a backend user with permissions to edit indexer configurations to index documents from arbitrary locations on the server file system by using path traversal sequences, which are characters used to navigate through the directory hierarchy to access files outside the intended folder.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46724

Affected Products

Ps Facetedsearch