PT-2026-45073 · Apache · Apache Solr
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Solr versions 9.4.0 through 9.10.1
Apache Solr version 10.0.0
Description
The Basic Authentication setup tool
bin/solr auth enable contains hardcoded credentials. This allows a remote attacker to gain full administrative access to the cluster using publicly known default credentials that are installed silently alongside the user-specified account. Approximately 1,154 internet-exposed Solr Admin assets have been identified.Recommendations
For Apache Solr versions 9.4.0 through 9.10.1, upgrade to version 9.11.0.
For Apache Solr version 10.0.0, upgrade to version 10.1.0.
As a temporary workaround, delete the template users (superadmin, admin, search, index) from
security.json or change their passwords.Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Solr