CVE-2024-45216PoC(apache / solr)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache solr systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path. This fake ending looks like an unprotected API path, however it is stripped off internally after authentication but before API routing. This issue affects Apache Solr: from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0. Users are recommended to upgrade to version 9.7.0, or 8.11.4, which fix the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • solr

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
solr

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-17: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 108-17
Signal classification1 categories
PoC
1100.0%
Full discourse1 post
  • Vulnerability Research Labs@vulnresearchlab
    PoC

    Apache Solr's authentication mechanism could be bypassed entirely. We reproduced the public vulnerability (CVE-2024-45216), built a working exploit, and verified the vendor's patch closes it. End-to-end reproduction cost: $5.32.

    Post summary

    The author rebuilt CVE‑2024‑45216, produced a working exploit demonstrating an authentication bypass, and confirmed that the vendor’s patch successfully mitigates the issue.

    0000037
    7 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachesolr---

Explore more