Page Access Bypass in TYPO3 Extension by TYPO3
CVE-2026-56092

7.6HIGH

Key Information:

Vendor

Typo3

Vendor
CVE Published:
25 August 2026

What is CVE-2026-56092?

This vulnerability arises from the extension's mishandling of frontend-group and subpage-inheritance restrictions during indexer sub-requests. As a result, it allows unauthorized users to circumvent access restrictions on cached pages, potentially exposing sensitive content intended for restricted access. This forged state is inadvertently stored in the shared rootline cache, thus compromising the integrity of the access control mechanisms.

Affected Version(s)

Extension "Apache Solr for TYPO3 - Enterprise Search" 13.0.0 < 13.1.4

Extension "Apache Solr for TYPO3 - Enterprise Search" 12.0.0 < 12.1.4

Extension "Apache Solr for TYPO3 - Enterprise Search" 0 < 11.6.6

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stefan Bürk
Rafael Kähm
EXT:solr team by dkd Internet Service GmbH
.