Page Access Bypass in TYPO3 Extension by TYPO3
CVE-2026-56092
7.6HIGH
Key Information:
- Vendor
Typo3
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-56092?
This vulnerability arises from the extension's mishandling of frontend-group and subpage-inheritance restrictions during indexer sub-requests. As a result, it allows unauthorized users to circumvent access restrictions on cached pages, potentially exposing sensitive content intended for restricted access. This forged state is inadvertently stored in the shared rootline cache, thus compromising the integrity of the access control mechanisms.
Affected Version(s)
Extension "Apache Solr for TYPO3 - Enterprise Search" 13.0.0 < 13.1.4
Extension "Apache Solr for TYPO3 - Enterprise Search" 12.0.0 < 12.1.4
Extension "Apache Solr for TYPO3 - Enterprise Search" 0 < 11.6.6
References
CVSS V4
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Stefan Bürk
Rafael Kähm
EXT:solr team by dkd Internet Service GmbH
