Improper Neutralization of Special Elements in Data Query Logic in Apache Solr for TYPO3 - Enterprise Search - CVE-2026-56096
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote attacker can can use this syntax to enumerate indexed field names and extract their stored values