CVE-2026-44825: CWE-798 Use of Hard-coded Credentials in Apache Software Foundation Apache Solr
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords. The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue. Not affected: * Clusters where bin/solr auth enable was not used to bootstrap BasicAuth * Clusters where template users have been assigned strong passwords after bootstrap
AI Analysis
Technical Summary
This vulnerability (CVE-2026-44825) in Apache Solr arises from hardcoded credentials embedded in the Basic Authentication setup tool used during bootstrap. The affected versions (9.4.0 through 9.10.1 and 10.0.0) install default template users (superadmin, admin, search, index) with known passwords alongside user accounts, enabling remote attackers to authenticate with these credentials and gain full administrative control over the Solr cluster. The issue does not affect clusters that did not use the BasicAuth bootstrap or where template user passwords were changed post-bootstrap. The vendor plans to fix this in upcoming versions 9.11.0 and 10.1.0.
Potential Impact
Successful exploitation allows a remote attacker to gain full administrative access to the Apache Solr cluster, compromising confidentiality, integrity, and availability. This includes the ability to control the cluster, modify data, and disrupt services. The CVSS 3.1 score is 8.1 (High), reflecting network attack vector, high impact on confidentiality, integrity, and availability, and no required privileges or user interaction.
Mitigation Recommendations
As no official patch or fix is currently available, immediate mitigation involves deleting the template users (superadmin, admin, search, index) from the security.json file or changing their passwords to strong, unique values. Clusters that did not use the BasicAuth bootstrap or have already assigned strong passwords to template users are not vulnerable. Upgrading to versions 9.11.0 or 10.1.0 once released will fully resolve the issue. Monitor the Apache Software Foundation advisories for the official release and patch availability.
CVE-2026-44825: CWE-798 Use of Hard-coded Credentials in Apache Software Foundation Apache Solr
Description
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords. The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue. Not affected: * Clusters where bin/solr auth enable was not used to bootstrap BasicAuth * Clusters where template users have been assigned strong passwords after bootstrap
CVSS v3.1
Score 8.1high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-44825) in Apache Solr arises from hardcoded credentials embedded in the Basic Authentication setup tool used during bootstrap. The affected versions (9.4.0 through 9.10.1 and 10.0.0) install default template users (superadmin, admin, search, index) with known passwords alongside user accounts, enabling remote attackers to authenticate with these credentials and gain full administrative control over the Solr cluster. The issue does not affect clusters that did not use the BasicAuth bootstrap or where template user passwords were changed post-bootstrap. The vendor plans to fix this in upcoming versions 9.11.0 and 10.1.0.
Potential Impact
Successful exploitation allows a remote attacker to gain full administrative access to the Apache Solr cluster, compromising confidentiality, integrity, and availability. This includes the ability to control the cluster, modify data, and disrupt services. The CVSS 3.1 score is 8.1 (High), reflecting network attack vector, high impact on confidentiality, integrity, and availability, and no required privileges or user interaction.
Mitigation Recommendations
As no official patch or fix is currently available, immediate mitigation involves deleting the template users (superadmin, admin, search, index) from the security.json file or changing their passwords to strong, unique values. Clusters that did not use the BasicAuth bootstrap or have already assigned strong passwords to template users are not vulnerable. Upgrading to versions 9.11.0 or 10.1.0 once released will fully resolve the issue. Monitor the Apache Software Foundation advisories for the official release and patch availability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-05-07T20:29:03.792Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1d4e75e29bf47b50cd4a02
Added to database: 6/1/2026, 9:18:45 AM
Last enriched: 6/1/2026, 9:33:56 AM
Last updated: 6/2/2026, 7:15:50 AM
Views: 36
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.