Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-44825

Опубликовано: 01 июн. 2026
Источник: nvd
CVSS3: 8.1
CVSS3: 9.8
EPSS Низкий

Описание

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.

As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords. The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue.

Not affected:

  • Clusters where bin/solr auth enable was not used to bootstrap BasicAuth
  • Clusters where template users have been assigned strong passwords after bootstrap

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*
Версия от 9.4.0 (включая) до 9.10.1 (включая)
cpe:2.3:a:apache:solr:10.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.02161
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.1
ubuntu
2 месяца назад

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords. The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue. Not affected: * Clusters where bin/solr auth enable was not used to bootstrap BasicAuth * Clusters where template users have been assigned strong passwords after bootstrap

CVSS3: 8.1
redhat
2 месяца назад

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords. The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue. Not affected: * Clusters where bin/solr auth enable was not used to bootstrap BasicAuth * Clusters where template users have been assigned strong passwords after bootstrap

CVSS3: 8.1
debian
2 месяца назад

Hardcoded credentials in the Basic Authentication setup tool (bin/solr ...

CVSS3: 8.1
github
2 месяца назад

Apache Solr has hardcoded credentials in the Basic Authentication setup tool

CVSS3: 8.1
fstec
2 месяца назад

Уязвимость утилиты командной строки bin/solr auth поискового сервера Apache Solr, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 80%
0.02161
Низкий

8.1 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-798