Improper authorization in Apache Solr - CVE-2026-22022

 

Improper authorization in Apache Solr - CVE-2026-22022

Published: January 22, 2026


Vulnerability identifier: #VU121931
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22022
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to improper input validation in the Rule Based Authorization Plugin. A remote authenticated user can bypass certain "predefined permission" rules in the RuleBasedAuthorizationPlugin under specific configurations and gain unauthorized access to the application. 


Affected software

Apache Solr
Communications Unified Assurance
Operational Decision Manager

How to mitigate CVE-2026-22022

Install updates from vendor's website.

Apache Solr - update to 9.10.1

External References

Related Security Bulletins