CVE-2026-47896
published 2026-07-03CVE-2026-47896: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.70%
49.0th percentile
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library).
This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017.
Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache_software_foundation | apache_lucene.net | >= 4.8.0-beta00005 < 4.8.0-beta00018 | 4.8.0-beta00018 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv4.08.9HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:L/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library).
ghsa_unreviewed·2026-07-03
CVE-2026-47896 [HIGH] CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library).
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library).
This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through 4.8.0-beta00017.
Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
VulDB
Apache Lucene.Net up to 4.8.0-beta00017 path traversal
vuldb·2026-07-03·CVSS 8.9
CVE-2026-47896 [HIGH] Apache Lucene.Net up to 4.8.0-beta00017 path traversal
A vulnerability, which was classified as critical, has been found in Apache Lucene.Net up to 4.8.0-beta00017. This issue affects some unknown processing. Performing a manipulation results in path traversal.
This vulnerability was named CVE-2026-47896. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-03
Published