CVE-2026-47897Disclosure(apache / lucene.net)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache lucene.net systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lucene.net

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
lucene.net

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-03: 1Mentions · 2026-07-05: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-05: 107-0307-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets4 URLs
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Lucene.⁠Net CVE-2026-47896: Unauthenticated arbitrary file read on the Replicator replication server https://www.openwall.com/lists/oss-security/2026/07/03/1 CVE-2026-47897: Arbitrary file write from malicious server to Replicator client https://www.openwall.com/lists/oss-security/2026/07/03/2 CVE-2026-47898: XXE https://www.openwall.com/lists/oss-security/2026/07/03/3

    Post summary

    The text announces three new Apache Lucene.Net vulnerabilities—CVE-2026-47896 (unauthenticated file read), CVE-2026-47897 (file write), and CVE-2026-47898 (XXE)—without providing any PoC, exploit, or patch information.

    01013487
    4.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Path Traversal in http://Lucene.Net Replicator (CVE-2026-47897) A path traversal vulnerability was discovered in the Apache http://Lucene.Net Replicator library (http://Lucene.Net.Replicator) that can allow file access outside the intended replication directories. The root cause is improper input validation/sanitization of filesystem paths, enabling traversal sequences to escape the expected base path. An attacker can exploit this by supplying crafted path values to replication-related APIs or endpoints that pass user-controlled input into file operations, typically requiring access to a service exposing the replicator functionality or the ability to influence replication requests/config. If exploited, the impact can include unauthorized read/write of files, leakage of sensitive data, tampering with replicated index artifacts, and potential service compromise depending on what files are reachable. 👉 Affected: http://Lucene.Net.Replicator 4.8.0-beta00005 to 4.8.0-beta00017 | Upgrade to 4.8.0-beta00018

    Post summary

    A high severity path traversal vulnerability (CVE-2026-47897) has been discovered in Lucene.Net Replicator, requiring an upgrade to version 4.8.0-beta00018 to mitigate the risk.

    0000085
    236 followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--
Appapachelucene.net4.8.0--

Explore more