CVE-2026-47898
published 2026-07-03CVE-2026-47898: Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.33%
24.8th percentile
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018.
Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache | lucene.net | — | — |
| apache_software_foundation | apache_lucene.net | >= 4.8.0-beta00005 < 4.8.0-beta00018 | 4.8.0-beta00018 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.04.0MEDIUMCVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Lucene.Net up to 4.8.0-beta00017 xml external entity reference
vuldb·2026-07-03·CVSS 4.0
CVE-2026-47898 [MEDIUM] Apache Lucene.Net up to 4.8.0-beta00017 xml external entity reference
A vulnerability has been found in Apache Lucene.Net up to 4.8.0-beta00017 and classified as problematic. The affected element is an unknown function. The manipulation leads to xml external entity reference.
This vulnerability is referenced as CVE-2026-47898. The attack can only be performed from a local environment. No exploit is available.
The affected component should be upgraded.
GHSA
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
ghsa_unreviewed·2026-07-03
CVE-2026-47898 [MEDIUM] CWE-611 Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018.
Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-03
Published