Access Control Flaw in TYPO3 Extension by TYPO3
CVE-2026-56093

6.3MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
25 August 2026

What is CVE-2026-56093?

A security issue exists within a TYPO3 extension that allows unauthorized users to perform document lookups without proper access restrictions. This vulnerability arises because the frontend detail-view document lookup fails to apply essential site-specific filters, permitting a user who knows or can guess a valid Solr document ID to access sensitive documents. This loophole can potentially expose sensitive data and compromise the integrity of the platform, highlighting the necessity for prompt remediation.

Affected Version(s)

Extension "Apache Solr for TYPO3 - Enterprise Search" 13.0.0 < 13.1.4

Extension "Apache Solr for TYPO3 - Enterprise Search" 12.0.0 < 12.1.4

Extension "Apache Solr for TYPO3 - Enterprise Search" 0 < 11.6.6

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seungbin Yang
Rafael Kähm
EXT:solr team by dkd Internet Service GmbH
.