Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-025 |
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed field names and extract their stored values through boolean- and range-based blind extraction techniques, independent of any site-specific configuration. | |
| Title | Information Disclosure in extension "Apache Solr for TYPO3 - Enterprise Search" (solr) | |
| Weaknesses | CWE-943 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T09:00:46.440Z
Reserved: 2026-06-18T17:29:39.231Z
Link: CVE-2026-56096
No data.
Status : Received
Published: 2026-08-25T09:17:31.647
Modified: 2026-08-25T09:17:31.647
Link: CVE-2026-56096
No data.
OpenCVE Enrichment
Updated: 2026-08-25T10:30:05Z