TYPO3 Extension: Unrestricted Solr Query Injection Enables Blind Data Extraction
CVE-2026-56096 Published on August 25, 2026

Information Disclosure in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed field names and extract their stored values through boolean- and range-based blind extraction techniques, independent of any site-specific configuration.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-56096 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
HIGH
Privileges Required:
NONE
User Interaction:
NONE

Weakness Type

Improper Neutralization of Special Elements in Data Query Logic

The application generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.


Products Associated with CVE-2026-56096

Want to know whenever a new CVE is published for TYPO3? stack.watch will email you.

 

Affected Versions

Extension "Apache Solr for TYPO3 - Enterprise Search":