Executive brief
Apache Solr for TYPO3 is a search indexing extension used to power site search across TYPO3 content management systems. In a shared Solr environment serving multiple sites, attackers can bypass site-specific access controls by injecting a custom siteHash filter parameter, allowing them to read public documents from other sites that should be isolated.
Technical details
The vulnerability is a broken access control issue (CWE-862, CWE-639) in the extension's query builder. A request-provided additionalFilters parameter allows an attacker to register a named siteHash filter before the system's own filter is applied. Since the query builder does not overwrite already-registered named filters, the attacker's filter takes precedence, bypassing the intended site-specific siteHash restriction. The vulnerability affects shared Solr cores serving multiple TYPO3 sites and is exploitable without authentication. The same root cause impacts the suggest top-results feature when enabled. Patched versions 11.2.8, 11.6.6, 12.1.4, and 13.1.4 are available.
Affected products
- Apache Solr for TYPO3 - Enterprise Search 11.2.7 and below, 11.5.0–11.6.5, 12.0.0–12.1.3, 13.0.0–13.1.3
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Versions 11.2.8, 11.6.6, 12.1.4, and 13.1.4 released