Signal is active with 1 mentions in latest observed window
Immediate actions
Patch apache lucene.net systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library).
This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00018.
Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
Apache Lucene.Net
CVE-2026-47896: Unauthenticated arbitrary file read on the Replicator replication server https://www.openwall.com/lists/oss-security/2026/07/03/1
CVE-2026-47897: Arbitrary file write from malicious server to Replicator client https://www.openwall.com/lists/oss-security/2026/07/03/2
CVE-2026-47898: XXE https://www.openwall.com/lists/oss-security/2026/07/03/3
Post summary
The text announces three new Apache Lucene.Net vulnerabilities—CVE-2026-47896 (unauthenticated file read), CVE-2026-47897 (file write), and CVE-2026-47898 (XXE)—without providing any PoC, exploit, or patch information.
🚨 HIGH - Path Traversal in http://Lucene.Net Replicator (CVE-2026-47897)
A path traversal vulnerability was discovered in the Apache http://Lucene.Net Replicator library (http://Lucene.Net.Replicator) that can allow file access outside the intended replication directories. The root cause is improper input validation/sanitization of filesystem paths, enabling traversal sequences to escape the expected base path. An attacker can exploit this by supplying crafted path values to replication-related APIs or endpoints that pass user-controlled input into file operations, typically requiring access to a service exposing the replicator functionality or the ability to influence replication requests/config. If exploited, the impact can include unauthorized read/write of files, leakage of sensitive data, tampering with replicated index artifacts, and potential service compromise depending on what files are reachable.
👉 Affected: http://Lucene.Net.Replicator 4.8.0-beta00005 to 4.8.0-beta00017 | Upgrade to 4.8.0-beta00018
Post summary
A high severity path traversal vulnerability (CVE-2026-47897) has been discovered in Lucene.Net Replicator, requiring an upgrade to version 4.8.0-beta00018 to mitigate the risk.