CVE-2026-56094
The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core serving multiple TYPO3 sites, a visitor can use this to read public documents belonging to another site. The same root cause also affects the suggest top-results path when suggest is enabled.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-943
- Published
- 2026-08-25
- Last modified
- 2026-08-25
Affected products
- TYPO3 Extension "Apache Solr for TYPO3 - Enterprise Search"
- TYPO3 Extension "Apache Solr for TYPO3 - Enterprise Search"
- TYPO3 Extension "Apache Solr for TYPO3 - Enterprise Search"
Weakness type
Related vulnerabilities
- CVE-2026-82060 — Insufficient Validation of Shard Key Values in MongoDB Server Leads to Query Operator Injection in Change Stream Post-Image Lookups
- CVE-2026-62906 — Microsoft Discovery Studio Information Disclosure Vulnerability
- CVE-2026-85167 — n8n before 2.36.2 Query Injection via Elasticsearch Firestore Nodes
- CVE-2026-63138 — Improper Neutralization of Special Elements in Data Query Logic in Kibana Leading to Information Disclosure
- CVE-2026-78691 — Unescaped backslash allows LIKE wildcard injection in AshSql string search
- CVE-2026-77846 — JSON path injection via unescaped get_path segments in AshSqlite
- CVE-2026-81528 — NoSQL injection via array replacement bypassing update shape validation in driver write path
- CVE-2026-81527 — NoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translation