Web Application Vulnerability in TYPO3 Extension by TYPO3
CVE-2026-56094
Key Information:
- Vendor
Typo3
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-56094?
The TYPO3 extension's architecture allows the registration of a request-provided additionalFilters parameter, which can lead to unauthorized document access across shared Solr cores. Specifically, when a named siteHash filter is registered prior to the system's default filter, it can enable unintended access to public documents from other TYPO3 sites. Additionally, this flaw can exploit the suggest top-results functionality when enabled, presenting a significant risk to user data and document privacy.
Affected Version(s)
Extension "Apache Solr for TYPO3 - Enterprise Search" 13.0.0 < 13.1.4
Extension "Apache Solr for TYPO3 - Enterprise Search" 12.0.0 < 12.1.4
Extension "Apache Solr for TYPO3 - Enterprise Search" 0 < 11.6.6
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
