
Apache Lucene.Net CVE-2026-47896: Unauthenticated arbitrary file read on the Replicator replication server https://www.openwall.com/lists/oss-security/2026/07/03/1 CVE-2026-47897: Arbitrary file write from malicious server to Replicator client https://www.openwall.com/lists/oss-security/2026/07/03/2 CVE-2026-47898: XXE https://www.openwall.com/lists/oss-security/2026/07/03/3
Post summary
Three new CVEs for Apache Lucene.Net have been disclosed, detailing unauthenticated file read, file write, and XXE vulnerabilities; no PoC, exploit, or patch information is provided.
