CVE-2026-56092

Summary

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.

Affected Software

VendorProductVersion RangeStatus
TYPO3Extension “Apache Solr for TYPO3 - Enterprise Search”13.0.0 < 13.1.4affected
TYPO3Extension “Apache Solr for TYPO3 - Enterprise Search”12.0.0 < 12.1.4affected
TYPO3Extension “Apache Solr for TYPO3 - Enterprise Search”0 < 11.6.6affected

Weaknesses

  • CWE-862: CWE-862 Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References