CVE-2026-56093

Summary

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.

Affected Software

VendorProductVersion RangeStatus
TYPO3Extension “Apache Solr for TYPO3 - Enterprise Search”13.0.0 < 13.1.4affected
TYPO3Extension “Apache Solr for TYPO3 - Enterprise Search”12.0.0 < 12.1.4affected
TYPO3Extension “Apache Solr for TYPO3 - Enterprise Search”0 < 11.6.6affected

Weaknesses

  • CWE-639: CWE-639 Authorization Bypass Through User-Controlled Key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References