CVE-2026-22444 describes an input validation vulnerability in the "create core" API of Apache Solr versions 8.6 through 9.10.0. This flaw allows authenticated, low-privilege users to bypass Solr's "allowPaths" security setting, potentially leading to the use of unexpected configsets and, on Windows systems, NTLM hash disclosure. The vulnerability has a CVSS score of 7.1 (High), indicating a network-based attack with low attack complexity and low privileges required, resulting in high confidentiality impact and low integrity impact. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the CVE has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.6, <= 9.10.0CPE match | cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:* | ||
>= 8.6.0, < 9.10.1CPE matchmatch criteria | cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache Solr: Insufficient file-access checking in standalone core-creation requests
Jan 21, 2026org.apache.solr/solr-core: Apache Solr: Insufficient file-access checking in standalone core-creation requests
Jan 21, 2026CVE-2026-22444: Apache Solr: Insufficient file-access checking in standalone core-creation requests
Jan 20, 2026