Junglewise Threat Intelligence

CVE-2026-82525: Exterro FTK Imager XXE injection vulnerability

CVE-2026-82525 · Severity: medium · CVSS 5.5 · Published 2026-09-03

Executive brief

Exterro FTK Imager is a digital forensics tool used to examine and analyze evidence in investigations. A vulnerability allows attackers to read sensitive files from an examiner's computer by crafting a malicious evidence archive. When a forensic examiner previews the malicious file, an attacker can steal confidential data stored on their system and exfiltrate it to an attacker-controlled location.

Technical details

The vulnerability is an XML External Entity (XXE) injection flaw in FTK Imager's handling of UFDR (Universal Forensic Data Repository) ZIP archives. The flaw exists in the XML parser when processing Report.xml files embedded in these archives. An attacker can inject malicious external entity references and XSLT stylesheets that leverage file:// URIs and msxsl:script execution to read arbitrary files from the host filesystem and exfiltrate their contents via HTTP requests to attacker-controlled endpoints. The attack is triggered when an examiner previews a crafted UFDR archive, requiring no authentication. The vulnerability was fixed in FTK Imager version 8.3.

Affected products

  • Exterro FTK Imager before 8.3

Timeline

  • 2026-09-03: disclosed
  • 2026: patched: Fixed in FTK Imager 8.3

References