CVE-2026-44825
published 2026-06-01CVE-2026-44825: Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote…
PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
2.89%
85.9th percentile
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.
As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords.
The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue.
Not affected:
* Clusters where bin/solr auth enable was not used to bootstrap BasicAuth
* Clusters where template users have been assigned strong passwords after bootstrap
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | solr | — | — |
| apache | solr | 9.4.0 – 9.10.1 | — |
| apache_software_foundation | apache_solr | — | — |
| apache_software_foundation | apache_solr | 9.4.0 – 9.10.1 | — |
| offline-knowledge-portal | rhokp-rhel9 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Flag any Apache Solr cluster (versions 9.4.0–9.10.1 and 10.0.0) where `bin/solr auth enable` was used to bootstrap BasicAuth; check security.json for the presence of template usernames: superadmin, admin, search, index. ↗
- →Monitor Solr admin API authentication logs for successful logins using the template usernames (superadmin, admin, search, index), especially from external/unexpected source IPs, as these indicate exploitation of hardcoded credentials. ↗
- →Clusters are NOT vulnerable if bin/solr auth enable was not used to bootstrap BasicAuth, or if template users have been assigned strong passwords after bootstrap — use these as triage filters to prioritize affected instances. ↗
- ·Only clusters that used `bin/solr auth enable` to set up BasicAuth are affected; clusters using other authentication bootstrap methods are not vulnerable. ↗
- ·Clusters where the template users (superadmin, admin, search, index) were assigned strong passwords after bootstrap are also not vulnerable. ↗
- ·A restart or reload of the Solr service may be necessary for changes to security.json (deletion or password change of template users) to be applied effectively. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
solr: Apache Solr: Remote attacker gains administrative access via hardcoded credentials in Basic Authentication setup.
vendor_redhat·2026-06-01·CVSS 9.8
CVE-2026-44825 [CRITICAL] CWE-1392 solr: Apache Solr: Remote attacker gains administrative access via hardcoded credentials in Basic Authentication setup.
solr: Apache Solr: Remote attacker gains administrative access via hardcoded credentials in Basic Authentication setup.
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.
As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords.
The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue.
Not affected:
* Clusters where bin/solr auth enable was not used to bootstrap Bas
GHSA
Apache Solr has hardcoded credentials in the Basic Authentication setup tool
ghsa·2026-06-01
CVE-2026-44825 [HIGH] CWE-798 Apache Solr has hardcoded credentials in the Basic Authentication setup tool
Apache Solr has hardcoded credentials in the Basic Authentication setup tool
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.
As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords.
The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue.
Not affected:
* Clusters where bin/solr auth enable was not used to bootstrap BasicAuth
* Clusters where template users ha
GHSA
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access
ghsa_unreviewed·2026-06-01
CVE-2026-44825 [HIGH] CWE-798 Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.
As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords.
The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue.
Not affected:
* Clusters where bin/solr auth enable was not used to bootstrap BasicAuth
* Clusters where template users have been assigned strong passwords after bootstrap
VulDB
Apache Solr up to 9.10.1/10.0.0 BasicAuth /bin/solr hard-coded key
vuldb·2026-05-30
CVE-2026-44825 [CRITICAL] Apache Solr up to 9.10.1/10.0.0 BasicAuth /bin/solr hard-coded key
A vulnerability categorized as critical has been discovered in Apache Solr up to 9.10.1/10.0.0. The impacted element is an unknown function of the file /bin/solr of the component BasicAuth. Executing a manipulation can lead to use of hard-coded cryptographic key
.
This vulnerability is handled as CVE-2026-44825. The attack can only be done within the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
VulnCheck
Apache Solr Use of Hard-coded Credentials
vulncheck·2026·CVSS 9.8
CVE-2026-44825 [CRITICAL] Apache Solr Use of Hard-coded Credentials
Apache Solr Use of Hard-coded Credentials
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account.
As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords.
The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue.
Not affected:
* Clusters where bin/solr auth enable was not used to bootstrap BasicAuth
* Clusters where template users have been assigned strong passwords a
No detection rules found.
Nuclei
Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials
nuclei·CVSS 9.8
CVE-2026-44825 [CRITICAL] Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials
Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials
Apache Solr 9.4.0 through 9.10.1 and 10.0.0 contain a hardcoded credentials vulnerability caused by default Basic Authentication template users in bin/solr auth enable, letting remote attackers gain full administrative access. Exploit requires use of default template users.
Template:
id: CVE-2026-44825
info:
name: Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials
author: pdteam,0x_Akoko
severity: high
description: |
Apache Solr 9.4.0 through 9.10.1 and 10.0.0 contain a hardcoded credentials vulnerability caused by default Basic Authentication template users in bin/solr auth enable, letting remote attackers gain full administrative access. Exploit requires use of default template users.
impact: |
Remote at
2026-06-01
Published
Exploited in the wild