8.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.
As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.jsonΒ or change their passwords.
The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue.
Not affected:
* Clusters where bin/solr auth enable was not used to bootstrap BasicAuth
* Clusters where template users have been assigned strong passwords after bootstrap
As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.jsonΒ or change their passwords.
The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue.
Not affected:
* Clusters where bin/solr auth enable was not used to bootstrap BasicAuth
* Clusters where template users have been assigned strong passwords after bootstrap
Basic Information
ID
CVE-2026-44825
Source
apache
Published
Jun 1, 2026 at 08:02
Affected Product
Vendor
Apache Software Foundation
Product
Apache Solr
Version
9.4.0
Affected Versions
Apache Software Foundation Apache Solr 9.4.0
Apache Software Foundation Apache Solr 10.0.0
Apache Software Foundation Apache Solr 10.0.0