CVE-2026-56094

Summary

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core serving multiple TYPO3 sites, a visitor can use this to read public documents belonging to another site. The same root cause also affects the suggest top-results path when suggest is enabled.

Affected Software

VendorProductVersion RangeStatus
TYPO3Extension “Apache Solr for TYPO3 - Enterprise Search”13.0.0 < 13.1.4affected
TYPO3Extension “Apache Solr for TYPO3 - Enterprise Search”12.0.0 < 12.1.4affected
TYPO3Extension “Apache Solr for TYPO3 - Enterprise Search”0 < 11.6.6affected

Weaknesses

  • CWE-943: CWE-943 Improper Neutralization of Special Elements in Data Query Logic

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References