CVE-2026-22444Disclosure(apache / solr)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache solr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths that should be disallowed by Solr's "allowPaths" security setting https://https://solr.apache.org/guide/solr/latest/configuration-guide/configuring-solr-xml.html#the-solr-element .  These read-only accesses can allow users to create cores using unexpected configsets if any are accessible via the filesystem.  On Windows systems configured to allow UNC paths this can additionally cause disclosure of NTLM "user" hashes.  Solr deployments are subject to this vulnerability if they meet the following criteria: * Solr is running in its "standalone" mode. * Solr's "allowPath" setting is being used to restrict file access to certain directories. * Solr's "create core" API is exposed and accessible to untrusted users.  This can happen if Solr's RuleBasedAuthorizationPlugin https://solr.apache.org/guide/solr/latest/deployment-guide/rule-based-authorization-plugin.html is disabled, or if it is enabled but the "core-admin-edit" predefined permission (or an equivalent custom permission) is given to low-trust (i.e. non-admin) user roles. Users can mitigate this by enabling Solr's RuleBasedAuthorizationPlugin (if disabled) and configuring a permission-list that prevents untrusted users from creating new Solr cores.  Users should also upgrade to Apache Solr 9.10.1 or greater, which contain fixes for this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • solr

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
solr

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-02: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-04-02: 104-02
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • HeroDevs@herodevs
    Disclosure

    🚨 Two new CVEs in Apache Solr — and they’re hitting where teams least expect it. CVE-2026-22022 and CVE-2026-22444 expose gaps in authorization and file access controls — putting sensitive configuration data, file systems, and even credentials at risk. Why this matters: ✔️ No authentication required for certain exploit paths ✔️ Sensitive data exposure through misconfigured APIs ✔️ Widely used versions affected across enterprise environments Moving from Solr 8 to 9+ can mean Java upgrades, API changes, and months of migration work... HeroDevs Never-Ending Support (NES) for Apache Solr & Lucene delivers patched, drop-in replacements for EOL versions — so you can remediate now and migrate on your timeline. Because security issues don’t wait for your roadmap. #ApacheSolr #Java #CVE #AppSec #OpenSourceSecurity #EOL #DevSecOps #HeroDevs

    Post summary

    Two new CVEs in Apache Solr expose authorization and file‑access control gaps, risking sensitive configuration data and credentials. HeroDevs NES offers patched replacements for affected EOL versions.

    10001112
    2.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachesolr---

Explore more