CVE-2026-56093: Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

Published Aug 25, 2026
·
Updated

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.

Affected Software

1 affected component
Apache Solr for TYPO3 - Enterprise Search (solr)

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Restrict access to Solr document-lookup endpoints used by the TYPO3 extension “Apache Solr for TYPO3 - Enterprise Search” (solr) so that requests enforce the same siteHash filter and frontend user access filter as the regular search path.

Event History

Aug 25, 2026
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Sites using the extension's frontend detail-view document lookup are exposed if Solr contains documents that should be limited by site-specific filtering or frontend user access controls. The regular search path applies those restrictions, but the affected lookup does not.

2

What does an attacker need to exploit it?

An attacker does not need authentication or user interaction, but must be able to obtain or guess a valid Solr document ID. Exploitation also depends on the detail-view lookup being reachable and on restricted documents being indexed in Solr.

3

What information could be disclosed?

The issue can disclose documents returned by the detail-view lookup that would not pass the current site's siteHash filter or frontend user access filter. The provided data indicates confidentiality impact only; it does not indicate integrity or availability impact.

4

How can I assess whether my site is affected?

Check whether the extension's frontend detail-view lookup is enabled or reachable, then test it with a valid Solr document ID for content that should be restricted to another site or to authenticated frontend users. If the lookup returns that document without the restrictions applied by regular search, the site is affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203