Vulnerability Description
The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed field names and extract their stored values through boolean- and range-based blind extraction techniques, independent of any site-specific configuration.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-56096?
CVE-2026-56096 is a documented vulnerability. The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthentica...
How severe is CVE-2026-56096?
CVSS scoring is not yet available for CVE-2026-56096. Check NVD for updates.
Is there a patch for CVE-2026-56096?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.