Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files (CVE-2025-24814)
Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authentication and authorization are vulnerable to a sort of privilege escalation wherein individual "trusted" configset files can be ignored in favor of potentially-untrusted replacements available elsewhere on the filesystem. These replacement config files are treated as "trusted" and can use "<lib>" tags to add to Solr's classpath, which an attacker might use to load malicious code as a searchComponent or other plugin. This issue affects all Apache Solr versions up through Solr 9.7. Users can protect against the vulnerability by enabling authentication and authorization on their Solr clusters or switching to SolrCloud (and away from "FileSystemConfigSetService"). Users are also recommended to upgrade to Solr 9.8.0, which mitigates this issue by disabling use of "<lib>" tags by default.
AI Analysis
Technical Summary
The vulnerability (CVE-2025-24814) affects Apache Solr instances that use the FileSystemConfigSetService component and run without authentication and authorization. Attackers can exploit this by replacing trusted configset files with arbitrary files elsewhere on the filesystem, which Solr treats as trusted. These files can include <lib> tags that allow loading of malicious code as search components or plugins, leading to privilege escalation. This affects all Solr versions before 9.8.0. The issue is addressed in Solr 9.8.0 by disabling <lib> tags by default. Alternative mitigations include enabling authentication and authorization or migrating to SolrCloud.
Potential Impact
An attacker with access to the Solr filesystem can escalate privileges by injecting malicious configuration files that Solr treats as trusted. This can lead to arbitrary code execution within the Solr process via malicious plugins or search components. The vulnerability requires the absence of authentication and authorization and use of the FileSystemConfigSetService component, limiting exposure to certain deployment configurations.
Mitigation Recommendations
Users should upgrade to Apache Solr version 9.8.0 or later, which disables the use of <lib> tags by default, mitigating this vulnerability. Alternatively, enabling authentication and authorization on Solr clusters or switching from FileSystemConfigSetService to SolrCloud will protect against this issue. These mitigations are recommended to prevent exploitation.
Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files (CVE-2025-24814)
Description
Core creation allows users to replace "trusted" configset files with arbitrary configuration Solr instances that (1) use the "FileSystemConfigSetService" component (the default in "standalone" or "user-managed" mode), and (2) are running without authentication and authorization are vulnerable to a sort of privilege escalation wherein individual "trusted" configset files can be ignored in favor of potentially-untrusted replacements available elsewhere on the filesystem. These replacement config files are treated as "trusted" and can use "<lib>" tags to add to Solr's classpath, which an attacker might use to load malicious code as a searchComponent or other plugin. This issue affects all Apache Solr versions up through Solr 9.7. Users can protect against the vulnerability by enabling authentication and authorization on their Solr clusters or switching to SolrCloud (and away from "FileSystemConfigSetService"). Users are also recommended to upgrade to Solr 9.8.0, which mitigates this issue by disabling use of "<lib>" tags by default.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2025-24814) affects Apache Solr instances that use the FileSystemConfigSetService component and run without authentication and authorization. Attackers can exploit this by replacing trusted configset files with arbitrary files elsewhere on the filesystem, which Solr treats as trusted. These files can include <lib> tags that allow loading of malicious code as search components or plugins, leading to privilege escalation. This affects all Solr versions before 9.8.0. The issue is addressed in Solr 9.8.0 by disabling <lib> tags by default. Alternative mitigations include enabling authentication and authorization or migrating to SolrCloud.
Potential Impact
An attacker with access to the Solr filesystem can escalate privileges by injecting malicious configuration files that Solr treats as trusted. This can lead to arbitrary code execution within the Solr process via malicious plugins or search components. The vulnerability requires the absence of authentication and authorization and use of the FileSystemConfigSetService component, limiting exposure to certain deployment configurations.
Mitigation Recommendations
Users should upgrade to Apache Solr version 9.8.0 or later, which disables the use of <lib> tags by default, mitigating this vulnerability. Alternatively, enabling authentication and authorization on Solr clusters or switching from FileSystemConfigSetService to SolrCloud will protect against this issue. These mitigations are recommended to prevent exploitation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BIT-solr-2025-24814
- Osv Schema Version
- 1.5.0
- Aliases
- ["CVE-2025-24814"]
- Ecosystems
- ["Bitnami"]
- Database Specific Severity
- Medium
Threat ID: 6aa005c3acd9273b49ab5bee
Added to database: 09/08/2026, 12:55:31 UTC
Last enriched: 09/08/2026, 13:17:37 UTC
Last updated: 09/10/2026, 22:04:12 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.