{"id":"CVE-2026-56093","summary":"Broken Access Control in extension \"Apache Solr for TYPO3 - Enterprise Search\" (solr)","details":"The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.","modified":"2026-08-28T11:30:33.879124082Z","published":"2026-08-25T09:00:48.858Z","database_specific":{"cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56093.json","cna_assigner":"TYPO3"},"references":[{"type":"WEB","url":"https://packagist.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56093.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56093"},{"type":"ADVISORY","url":"https://typo3.org/security/advisory/typo3-ext-sa-2026-025"},{"type":"PACKAGE","url":"https://github.com/TYPO3-Solr/ext-solr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/typo3-solr/ext-solr","events":[{"introduced":"0c9d7282dde216e98ea99d25130fb1e974952173"},{"fixed":"722363e5a62fa52c3bde1da402a7e483b331d5ed"},{"introduced":"15216391ffb46df703c7021cbf8f3353d3d25389"},{"fixed":"20d79a23a482c55dfd1f3e67cbc346d3fa7ef279"},{"introduced":"0"},{"fixed":"47ecacaaa3949054e6d0b2d32c5f56a2bfb8d75b"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"13.0.0"},{"fixed":"13.1.4"},{"introduced":"12.0.0"},{"fixed":"12.1.4"},{"introduced":"0"},{"fixed":"11.6.6"}]}}],"versions":["12.1.3","13.1.3","13.1.2","12.1.2","12.1.1","13.1.1","12.1.0","13.1.0","12.0.7","13.0.3","13.0.2","12.0.6","13.0.1","13.0.0","11.6.0","11.5.7","12.0.5","12.0.4","12.0.3","11.5.6","12.0.2","11.5.5","12.0.1","11.5.4","12.0.0","11.5.3","11.5.2","11.5.1","11.5.0","11.5.0-rc-3","11.5.0-rc-2","11.5.0-rc-1","11.5.0-beta-2","11.5.0-beta-1","11.5.0-pre-alpha-1","3.1.0","3.1.0-beta","3.0.0","2.8.0","2.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-56093.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}