Use of hard-coded credentials in Apache Solr - CVE-2026-44825

 

Use of hard-coded credentials in Apache Solr - CVE-2026-44825

Published: June 4, 2026


Vulnerability identifier: #VU133400
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44825
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain full administrative access to the cluster.

The vulnerability exists due to hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) when bootstrapping BasicAuth. A remote attacker can authenticate with publicly known default credentials to gain full administrative access to the cluster.

Only clusters where BasicAuth was bootstrapped using the tool are affected.


Affected software

Apache Solr
Operational Decision Manager

How to mitigate CVE-2026-44825

Install security update from vendor's website.

Apache Solr - addressed in versions 9.11.0, 10.1.0

External References

Related Security Bulletins