Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-22444

Apache Solr: create core API does not fully enforce allowPaths

Technology

Apache Solr

CVSS Score

7.1 / 10.0

Affected Versions

8.6 to 9.10.0

Upstream Fix

9.10.1

Published

January 21, 2026

OSSeva Coverage

Fixed upstream

Description

The create core API lacks input validation on some parameters, so Solr can check for and read file system paths that the allowPaths setting should block. A user can then create cores from unexpected configsets, and on Windows with UNC paths allowed the request can leak NTLM user hashes. It affects standalone mode where allowPaths is in use and the create core API is open to untrusted users. Rated moderate by the Solr PMC. Fixed in 9.10.1.

Upstream record: NVD · CVE.org

Is your Apache Solr deployment affected?

If you're running 8.6 to 9.10.0, you need this patch. Book a discovery call to get covered.