Description
The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.
Published: 2026-08-25
Score: 7.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises in the Apache Solr for TYPO3 extension, which forces empty frontend-group and subpage‑inheritance restrictions onto page records during indexer sub‑requests. This forged state is then stored in the shared rootline cache, enabling anonymous visitors to bypass extendToSubpages‑inherited access restrictions on cached pages. As a result, non‑authenticated users can read content that should otherwise be protected, compromising confidentiality and potentially revealing sensitive information.

Affected Systems

TYPO3 sites that have installed the "Apache Solr for TYPO3 - Enterprise Search" extension are affected. No specific version ranges are listed in the advisory, but any installation using this extension may be vulnerable until a fix is applied.

Risk and Exploitability

The vulnerability carries a CVSS v3.1 base score of 7.6, indicating high severity. EPSS data is not available and the issue is not listed in CISA KEV catalog, but the lack of exploitation metrics does not mean the risk is low. The likely attack vector is a remote request that triggers the extension’s indexer, which then writes the forged page state into the cache. The persistent cache entries allow anonymous visitors to repeatedly obtain access to protected content until the cache is purged or the vulnerability is patched.

Generated by OpenCVE AI on August 25, 2026 at 10:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the "Apache Solr for TYPO3 - Enterprise Search" extension to the latest patched release or disable the extension if it is no longer required.
  • Clear the shared rootline cache or rebuild it to remove any forged cache entries that were created while the vulnerability existed.
  • Verify that anonymous access restrictions remain in place and monitor crawler activity that may trigger indexer sub‑requests, applying stricter permissions or firewall rules if necessary.

Generated by OpenCVE AI on August 25, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.
Title Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr)
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TYPO3

Published:

Updated: 2026-08-25T09:00:49.567Z

Reserved: 2026-06-18T17:29:39.231Z

Link: CVE-2026-56092

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T09:17:30.807

Modified: 2026-08-25T09:17:30.807

Link: CVE-2026-56092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T10:30:05Z

Weaknesses