Web Application Vulnerability in TYPO3 Extension by TYPO3
CVE-2026-56094

6.3MEDIUM

Key Information:

Vendor

Typo3

Vendor
CVE Published:
25 August 2026

What is CVE-2026-56094?

The TYPO3 extension's architecture allows the registration of a request-provided additionalFilters parameter, which can lead to unauthorized document access across shared Solr cores. Specifically, when a named siteHash filter is registered prior to the system's default filter, it can enable unintended access to public documents from other TYPO3 sites. Additionally, this flaw can exploit the suggest top-results functionality when enabled, presenting a significant risk to user data and document privacy.

Affected Version(s)

Extension "Apache Solr for TYPO3 - Enterprise Search" 13.0.0 < 13.1.4

Extension "Apache Solr for TYPO3 - Enterprise Search" 12.0.0 < 12.1.4

Extension "Apache Solr for TYPO3 - Enterprise Search" 0 < 11.6.6

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Seungbin Yang
Rafael Kähm
EXT:solr team by dkd Internet Service GmbH
.