CVE-2026-56092: Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

Published Aug 25, 2026
·
Updated

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.

Affected Software

1 affected component
apache/solr

Event History

Aug 25, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Anonymous visitors can exploit it, but exploitation depends on the affected page having extendToSubpages-inherited frontend access restrictions and a poisoned shared rootline cache entry.

2

What conditions are required for the access-control bypass?

The Solr indexer must make sub-requests that force empty frontend-group and subpage-inheritance restrictions onto page records. That forged state must then be persisted in the shared rootline cache for pages relying on inherited access restrictions.

3

How can administrators determine whether they may be affected?

Review whether the Apache Solr for TYPO3 - Enterprise Search extension is installed and whether protected pages use frontend-group restrictions inherited through extendToSubpages. Also investigate whether anonymous users can access content on cached pages that should be restricted by those inherited rules.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203