PT-2026-81224 · Typo3 · Typo3

·

CVE-2026-56095

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v4.0

7.7

High

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The indexer of the extension uses the PHP unserialize() function to process field values returned by content object rendering when transferring multi-value data for SOLR CLASSIFICATION, SOLR MULTIVALUE, and SOLR RELATION content object types. This occurs instead of using a safe data format. If user-generated content stored in the TYPO3 database reaches an indexed field, it creates a PHP Object Injection surface, which allows an attacker to inject malicious serialized objects into the application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56095

Affected Products

Typo3