TYPO3 solr Extension Frontend Detail-View Bypass: SiteHash & FE Filters Not Applied
CVE-2026-56093 Published on August 25, 2026
Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.
Vulnerability Analysis
CVE-2026-56093 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Type
What is an Insecure Direct Object Reference / IDOR Vulnerability?
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVE-2026-56093 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.
Products Associated with CVE-2026-56093
Want to know whenever a new CVE is published for TYPO3? stack.watch will email you.
Affected Versions
Extension "Apache Solr for TYPO3 - Enterprise Search":- Version 13.0.0 and below 13.1.4 is affected.
- Version 12.0.0 and below 12.1.4 is affected.
- Before 11.6.6 is affected.