SB2026082644 - Multiple vulnerabilities in Apache Solr for TYPO3 - Enterprise Search extension for TYPO3
Published: August 26, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Missing Authorization (CVE-ID: CVE-2026-56092)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to missing authorization. A remote user can bypass extendToSubpages-inherited access restrictions on cached pages.
2) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-56093)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter. A remote user can retrieve documents through this lookup without the same access restrictions enforced elsewhere.
3) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-56094)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied. A remote attacker can read public documents belonging to another site.
4) Deserialization of Untrusted Data (CVE-ID: CVE-2026-56095)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote user can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
5) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-56096)
CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote attacker can can use this syntax to enumerate indexed field names and extract their stored values
Remediation
Install update from vendor's website.