Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-025 |
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere. | |
| Title | Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr) | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:48.858Z
Reserved: 2026-06-18T17:29:39.231Z
Link: CVE-2026-56093
No data.
Status : Received
Published: 2026-08-25T09:17:31.030
Modified: 2026-08-25T09:17:31.030
Link: CVE-2026-56093
No data.
OpenCVE Enrichment
Updated: 2026-08-25T10:30:05Z
-
CWE-639
Authorization Bypass Through User-Controlled Key