PHP Object Injection Vulnerability in TYPO3 Extension by TYPO3 GmbH
CVE-2026-56095
Key Information:
- Vendor
Typo3
- Vendor
- CVE Published:
- 25 August 2026
What is CVE-2026-56095?
A vulnerability exists in TYPO3 extensions where the indexer improperly handles multi-value data for SOLR_CLASSIFICATION, SOLR_MULTIVALUE, and SOLR_RELATION content object types. By utilizing PHP's unserialize() function without sufficient validation, the vulnerability permits crafted user-generated content saved in the TYPO3 database to exploit this weakness. This enables potential attackers to inject malicious objects, leading to severe consequences for data integrity and application security.
Affected Version(s)
Extension "Apache Solr for TYPO3 - Enterprise Search" 13.0.0 < 13.1.4
Extension "Apache Solr for TYPO3 - Enterprise Search" 12.0.0 < 12.1.4
Extension "Apache Solr for TYPO3 - Enterprise Search" 0 < 11.6.6
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
