Extension "Apache Solr for TYPO3 - Enterprise Search" vulnerability

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without the same access restrictions enforced elsewhere.

Published 25 Aug 2026Updated 17 Sep 20261 sources
CVSS 6.3

Source timeline

CVE record published by NVDView source ↗