Apache Solr 10.0.0 < 10.1.0 JWT Authentication Unauthenticated Access

medium Web App Scanning Plugin ID 115561

Synopsis

Apache Solr 10.0.0 < 10.1.0 JWT Authentication Unauthenticated Access

Description

Apache Solr versions 9.0.0 through 9.10.1 and 10.0.0 are affected by an authentication weakness in the JWT Authentication Plugin. Contrary to the documentation, which states that the 'blockUnknown' setting defaults to true since Solr 9.0, the code default has always been false. Deployments using 'solr.JWTAuthPlugin' without explicitly setting 'blockUnknown' to true, and without an authorization plugin denying unauthenticated users, allow unauthenticated requests.

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update to Apache Solr version 10.1.0 or latest. Alternatively, explicitly set 'blockUnknown' to true in the JWT Authentication Plugin configuration of security.json.

See Also

https://solr.apache.org/guide/solr/latest/deployment-guide/jwt-authentication-plugin.html

https://solr.apache.org/security-news.html#jwt-authentication-blockunknown-default-allows-unauthenticated-access-contrary-to-documentation

Plugin Details

Severity: Medium

ID: 115561

Type: Version Based

Published: 10/2/2026

Updated: 10/2/2026

Scan Template: api, basic, full, pci, scan

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 4.8

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CVSS Score Source: Tenable

Vulnerability Information

CPE: cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 5/19/2026

Reference Information