Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://typo3.org/security/advisory/typo3-ext-sa-2026-025 |
|
Tue, 25 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages. | |
| Title | Broken Access Control in extension "Apache Solr for TYPO3 - Enterprise Search" (solr) | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TYPO3
Published:
Updated: 2026-08-25T13:59:54.064Z
Reserved: 2026-06-18T17:29:39.231Z
Link: CVE-2026-56092
Updated: 2026-08-25T13:59:49.785Z
Status : Received
Published: 2026-08-25T09:17:30.807
Modified: 2026-08-25T14:16:52.590
Link: CVE-2026-56092
No data.
OpenCVE Enrichment
Updated: 2026-08-25T10:30:05Z