CVE-2026-82525 PUBLISHED

Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing

Assigner: VulnCheck
Reserved: 29.08.2026 Published: 03.09.2026 Updated: 03.09.2026

Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file inside a UFDR ZIP evidence item. Attackers can craft a malicious UFDR archive that, when previewed by an examiner, causes the XML parser to resolve file:// external entity references and execute msxsl:script within the external stylesheet to exfiltrate the resolved file contents to an attacker-controlled endpoint via a generated image URL.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor Exterro
Product FTK Imager
Versions Default: affected
  • affected from 0 to 8.3 (excl.)

Credits

  • Mobasi Security Team finder

References

Problem Types

  • Improper Restriction of XML External Entity Reference CWE
  • Inclusion of Functionality from Untrusted Control Sphere CWE