logo

Search Engine Exposed: Apache Solr Flaws Leak Data & Bypass Auth

ID: 772ae0b8-55be-528d-b3eb-4f201efaa2f4

STIX ID: report--772ae0b8-55be-528d-b3eb-4f201efaa2f4

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-01-21

Date Updated: 2026-04-23

Author: Ddos

...
...

Executive summary: Apache Solr versions from 5.3 through 9.10.0 are affected by two moderate vulnerabilities: CVE-2026-22444 (insufficient input validation in the create core API allowing unauthorized filesystem reads and potential NTLM hash exposure on Windows when UNC paths are permitted) and CVE-2026-22022 (an input-validation flaw in RuleBasedAuthorizationPlugin that can permit API access bypass when permission rules are misconfigured). Apache has released Solr 9.10.1 to address both issues; administrators should patch immediately or apply recommended mitigations such as enabling and strictly configuring the RuleBasedAuthorizationPlugin and explicitly assigning the "all" permission to an administrative role.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.