TYPO3 solr Extension Frontend Detail-View Bypass: SiteHash & FE Filters Not Applied
CVE-2026-56093 Published on August 25, 2026

Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-56093 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

What is an Insecure Direct Object Reference / IDOR Vulnerability?

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

CVE-2026-56093 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.


Products Associated with CVE-2026-56093

Want to know whenever a new CVE is published for TYPO3? stack.watch will email you.

 

Affected Versions

Extension "Apache Solr for TYPO3 - Enterprise Search":