Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4241 articles · 196928 vulns · 37/41 feeds (7d)
← Back to list
—
CVE-2026-56094PATCHED
typo3 · extension "apache solr for typo3 - enterprise search"

Information Disclosure in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)

Description

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core serving multiple TYPO3 sites, a visitor can use this to read public documents belonging to another site. The same root cause also affects the suggest top-results path when suggest is enabled.

Affected Products

VendorProductVersions
typo3extension "apache solr for typo3 - enterprise search"13.0.0, 12.0.0, 0

References

  • https://typo3.org/security/advisory/typo3-ext-sa-2026-025(vendor-advisory)

Related News (1 articles)

Tier C
VulDB6h ago
CVE-2026-56094 | TYPO3 Apache Solr up to 11.6.5/12.1.3/13.1.3 SiteHash Filter additionalFilters information disclosure
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
13.1.412.1.411.6.6
CWECWE-943
PublishedAug 25, 2026
Trending Score20
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-77136EXPKEV
Server-Side Template Injection in extension "powermail" (powermail)
Trending: 92
NONECVE-2026-77138
Remote Code Execution in extension "HTML5 Video Player vs. Powermail" (html5videoplayer_powermail)
Trending: 34
NONECVE-2026-77143
Broken Access Control in extension "Forum" (pforum)
Trending: 29
NONECVE-2026-77141
Broken Access Control in extension "Club Directory" (clubdirectory)
Trending: 29
NONECVE-2026-77142
Broken Access Control in extension "Industry Directory" (yellowpages2)
Trending: 29

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Aug 25, 2026