CVE-2026-56094: TYPO3 Extension Apache Solr For TYPO3 - Enterprise Search

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core serving multiple TYPO3 sites, a visitor can use this to read public documents belonging to another site. The same root cause also affects the suggest top-results path when suggest is enabled.

Affected products

  • TYPO3 Extension Apache Solr For TYPO3 - Enterprise Search: from 13.0.0, before 13.1.4 (fixed in 13.1.4); from 12.0.0, before 12.1.4 (fixed in 12.1.4); from 11.5.0, before 11.6.6 (fixed in 11.6.6); before 11.2.8 (fixed in 11.2.8)

Published 2026-08-25. Last modified 2026-09-17.