CVE-2026-22444
Last modified
CVE-2026-22444 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths that should be disallowed by Solr's "allowPaths" security setting https://https://solr.apache.org/guide/solr/latest/configuration-guide/configuring-solr-xml.html#the-solr-element . These read-only accesses can allow users to create cores using unexpected configsets if any are accessible via the filesystem. On Windows systems configured to allow UNC paths this can additionally cause disclosure of NTLM "user" hashes. Solr deployments are subject to this vulnerability if they meet the following criteria: * Solr is running in its "standalone" mode. * Solr's "allowPath" setting is being used to restrict file access to certain directories. * Solr's "create core" API is exposed and accessible to untrusted users. This can happen if Solr's RuleBasedAuthorizationPlugin https://solr.apache.org/guide/solr/latest/deployment-guide/rule-based-authorization-plugin.html is disabled, or if it is enabled but the "core-admin-edit" predefined permission (or an equivalent custom permission) is given to low-trust (i.e. non-admin) user roles. Users can mitigate this by enabling Solr's RuleBasedAuthorizationPlugin (if disabled) and configuring a permission-list that prevents untrusted users from creating new Solr cores. Users should also upgrade to Apache Solr 9.10.1 or greater, which contain fixes for this issue.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API parameters, which can cause Solr to check the existence of and attempt to read file-system paths that should be disallowed by Solr's "allowPaths" security setting https://https://solr.apache.org/guide/solr/latest/configuration-guide/configuring-solr-xml.html#the-solr-element . These read-only accesses can allow users to create cores using unexpected configsets if any are accessible via the filesystem. On Windows systems configured to allow UNC paths this can additionally cause disclosure of NTLM "user" hashes. Solr deployments are subject to this vulnerability if they meet the following criteria: * Solr is running in its "standalone" mode. * Solr's "allowPath" setting is being used to restrict file access to certain directories. * Solr's "create core" API is exposed and accessible to untrusted users. This can happen if Solr's RuleBasedAuthorizationPlugin https://solr.apache.org/guide/solr/latest/deployment-guide/rule-based-authorization-plugin.html is disabled, or if it is enabled but the "core-admin-edit" predefined permission (or an equivalent custom permission) is given to low-trust (i.e. non-admin) user roles. Users can mitigate this by enabling Solr's RuleBasedAuthorizationPlugin (if disabled) and configuring a permission-list that prevents untrusted users from creating new Solr cores. Users should also upgrade to Apache Solr 9.10.1 or greater, which contain fixes for this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Solr | >= 8.6.0, < 9.10.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-22444?
How severe is CVE-2026-22444?
How do I fix CVE-2026-22444?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22439Improper Control of Filename for Include/Require Statement i…8.1
- CVE-2026-2244A vulnerability in Google Cloud Vertex AI Workbench from 7/2…8.4
- CVE-2026-22440Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-22441Improper Control of Filename for Include/Require Statement i…8.1
- CVE-2026-22442Improper Control of Filename for Include/Require Statement i…8.1
- CVE-2026-22443Improper Control of Filename for Include/Require Statement i…8.1
- CVE-2026-22445Missing Authorization vulnerability in Proptech Plugin Apimo…5.3
- CVE-2026-22446Improper Control of Filename for Include/Require Statement i…8.1
- CVE-2026-22447Missing Authorization vulnerability in Select-Themes Prowess…5.3
- CVE-2026-22448Improper Limitation of a Pathname to a Restricted Directory …7.5
- CVE-2026-22449Improper Control of Filename for Include/Require Statement i…8.1
- CVE-2026-2245A vulnerability was identified in CCExtractor up to 183. Thi…3.3
Are you affected by CVE-2026-22444?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
