CVE-2026-46724
Severity CVSS v4.0:
MEDIUM
Type:
CWE-22
Path Traversal
Publication date:
19/05/2026
Last modified:
19/05/2026
Description
The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents from arbitrary locations on the server file system through path traversal sequences.
Impact
Base Score 4.0
5.90
Severity 4.0
MEDIUM



