CVE-2026-56096: TYPO3 Extension Apache Solr For TYPO3 - Enterprise Search
Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed field names and extract their stored values through boolean- and range-based blind extraction techniques, independent of any site-specific configuration.
Affected products
- TYPO3 Extension Apache Solr For TYPO3 - Enterprise Search: from 13.0.0, before 13.1.4 (fixed in 13.1.4); from 12.0.0, before 12.1.4 (fixed in 12.1.4); from 11.5.0, before 11.6.6 (fixed in 11.6.6); before 11.2.8 (fixed in 11.2.8)
Published 2026-08-25. Last modified 2026-09-17.