SCA: security update for org.apache.solr:solr-core (GHSA-vc2w-4v3p-2mqw)

high Tenable Self-Hosted Container Security Plugin ID 436886

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The "create core" API of Apache Solr 8.6 through 9.10.0 lacks sufficient input validation on some API
parameters, which can cause Solr to check the existence of and attempt to read file-system paths that
should be disallowed by Solr's "allowPaths" security setting
https://https://solr.apache.org/guide/solr/latest/configuration-guide/configuring-solr-xml.html#the-solr-
element . These read-only accesses can allow users to create cores using unexpected configsets if any are
accessible via the filesystem. On Windows systems configured to allow UNC paths this can additionally
cause disclosure of NTLM "user" hashes. Solr deployments are subject to this vulnerability if they meet
the following criteria: * Solr is running in its "standalone" mode. * Solr's "allowPath" setting is being
used to restrict file access to certain directories. * Solr's "create core" API is exposed and accessible
to untrusted users. This can happen if Solr's RuleBasedAuthorizationPlugin
https://solr.apache.org/guide/solr/latest/deployment-guide/rule-based-authorization-plugin.html is
disabled, or if it is enabled but the "core-admin-edit" predefined permission (or an equivalent custom
permission) is given to low-trust (i.e. non-admin) user roles. Users can mitigate this by enabling Solr's
RuleBasedAuthorizationPlugin (if disabled) and configuring a permission-list that prevents untrusted users
from creating new Solr cores. Users should also upgrade to Apache Solr 9.10.1 or greater, which contain
fixes for this issue. (CVE-2026-22444)

See Also

https://github.com/advisories/GHSA-vc2w-4v3p-2mqw

Plugin Details

Severity: High

ID: 436886

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/22/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 52.04

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:P/A:N

CVSS Score Source: CVE-2026-22444

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/21/2026

Vulnerability Publication Date: 1/21/2026

Reference Information

CVE: CVE-2026-22444

cwe: CWE-20