CVE-2026-82525 MEDIUM

CVE-2026-82525: Exterro FTK Imager < 8.3 XXE via Report.xml XSLT Processing

Vendor Exterro
Product FTK Imager
Weakness CWE-611 · XXE
Published September 3, 2026
Last update September 14, 2026

CVSS base score

6.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file inside a UFDR ZIP evidence item. Attackers can craft a malicious UFDR archive that, when previewed by an examiner, causes the XML parser to resolve file:// external entity references and execute msxsl:script within the external stylesheet to exfiltrate the resolved file contents to an attacker-controlled endpoint via a generated image URL.

Key dates

02Disclosure timeline

September 3, 2026 CVE published
September 14, 2026 Record updated

Related vulnerabilities

04Related CVE