Improper Neutralization of Special Elements in Data Query Logic in Apache Solr for TYPO3 - Enterprise Search - CVE-2026-56094
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied. A remote attacker can read public documents belonging to another site.