Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-22444
Apache Solr: create core API does not fully enforce allowPaths
Technology
Apache Solr
CVSS Score
7.1 / 10.0
Affected Versions
8.6 to 9.10.0
Upstream Fix
9.10.1
Published
January 21, 2026
OSSeva Coverage
Fixed upstream
Description
The create core API lacks input validation on some parameters, so Solr can check for and read file system paths that the allowPaths setting should block. A user can then create cores from unexpected configsets, and on Windows with UNC paths allowed the request can leak NTLM user hashes. It affects standalone mode where allowPaths is in use and the create core API is open to untrusted users. Rated moderate by the Solr PMC. Fixed in 9.10.1.
Is your Apache Solr deployment affected?
If you're running 8.6 to 9.10.0, you need this patch. Book a discovery call to get covered.