S4E just found a high top 10 tcp port service scan
high·Misconfiguration·Updated Jul 29, 2026

CVE-2026-44825 Scanner

CVE-2026-44825 Scanner - Hard-Coded Credentials vulnerability in Apache Solr

Est. Time~1 minutes
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-44825
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords. The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue. Not affected: * Clusters where bin/solr auth enable was not used to bootstrap BasicAuth * Clusters where template users have been assigned strong passwords after bootstrap

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Solrby Apache Software Foundation
9.4.0
Updated Aug 19, 2026View on NVD →
Detail

Apache Solr is a highly reliable and scalable search platform used by many organizations for enterprise search and storage. It is commonly used by developers and IT teams who require a robust and flexible solution for indexing and searching documents and databases. Companies utilize Solr in various applications such as e-commerce product searches, data archiving, and knowledge management systems. The software provides powerful search and real-time indexing capabilities, allowing optimized data retrieval. Solr's extensive plugin architecture and customizable components make it a preferred choice for businesses looking to create search-oriented applications. Due to its open-source nature, organizations across diverse sectors, including finance, government, and technology, deploy Solr to handle large volumes of data efficiently.

The vulnerability detected in Apache Solr involves hard-coded credentials which can be exploited by remote attackers. This issue arises because the software uses default Basic Authentication template users without appropriate adjustments in the security configuration. Requiring attackers to use predetermined credentials, this flaw compromises administrative access. It particularly affects versions 9.4.0 through 9.10.1 and 10.0.0 of Apache Solr. If exploited, unauthorized users could leverage these hard-coded details to execute administrative functions. Addressing this vulnerability would involve updating to newer software versions or configuring secure authentication practices.

The technical details involve the usage of default credentials related to Basic Authentication within Apache Solr's administrative setup. The authentication templates are located in the bin/solr auth enable directory, which attackers can exploit due to their default nature. Remote attackers must employ the default template user credentials to gain administrative access. The templates do not require prior knowledge of unique passwords, thus posing a considerable security threat. This issue is confirmed by observing responses to unauthorized access attempts, where the server does not challenge credential provision adequately. The vulnerability becomes apparent upon analyzing HTTP response codes and specific authentication headers during requests to the Solr admin panel.

When exploited by malicious entities, this vulnerability allows complete administrative control over the affected Solr instance. This can lead to unauthorized access to sensitive data, potential data manipulation, and system damage or downtime. Attackers with administrative access could disrupt the availability and integrity of the search services within the organization. They may extract or tamper with indexed data, compromising confidentiality and regulatory compliance. Additionally, attackers could leverage administrative rights to pivot within networks, accessing other connected systems or applications, amplifying the security impact across the entire infrastructure.

REFERENCES

Solution Advice
  • Upgrade Apache Solr to version 9.11.0, 10.1.0, or later.
  • Remove or modify default credentials in the security configuration file to ensure personalized credentials are used.
  • Enable secure, unique authentication mechanisms for accessing Solr admin panels.
  • Regularly audit security settings and monitor for unauthorized access attempts.
  • Consult Apache Solr security guides to implement best practices in configuration management.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.