CVE-2026-82525
Received Received - Intake

Exterro FTK Imager XML External Entity Injection

Vulnerability report for CVE-2026-82525, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: VulnCheck

Description

Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file inside a UFDR ZIP evidence item. Attackers can craft a malicious UFDR archive that, when previewed by an examiner, causes the XML parser to resolve file:// external entity references and execute msxsl:script within the external stylesheet to exfiltrate the resolved file contents to an attacker-controlled endpoint via a generated image URL.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
exterro ftk_imager to 8.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an XML External Entity (XXE) injection vulnerability in Exterro FTK Imager before version 8.3. Attackers can embed malicious external entity references and XSLT stylesheets in a Report.xml file within a UFDR ZIP evidence item. When an examiner previews the crafted archive, the XML parser resolves file:// references and executes attacker-controlled scripts to read arbitrary files from the host filesystem and exfiltrate them to an attacker-controlled endpoint.

Detection Guidance

To detect this vulnerability, monitor for suspicious UFDR ZIP files containing Report.xml with external entity references or XSLT stylesheets. Check for unusual network traffic from FTK Imager processes that may indicate file exfiltration attempts.

Impact Analysis

If you use Exterro FTK Imager versions before 8.3, an attacker could craft a malicious UFDR archive that, when previewed, allows them to read sensitive files from your system. This could lead to unauthorized access to confidential data, intellectual property, or other sensitive information stored on the machine running the software.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating compliance requirements such as GDPR (data protection) and HIPAA (health information privacy). Unauthorized access to sensitive data may result in legal penalties, fines, or reputational damage due to non-compliance with regulatory standards.

Mitigation Strategies

Upgrade to FTK Imager 8.3 or later to address the XXE vulnerability. Avoid opening UFDR archives from untrusted sources and implement network monitoring to detect exfiltration attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82525. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart