{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aapachesolr/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-22444"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Solr (\u003c 9.10.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","apache-solr"],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eCVE-2026-22444 is a critical vulnerability affecting Apache Solr versions prior to 9.10.1. The flaw resides in the 'create core' API, specifically within the CoreContainer.java component, where the application fails to perform adequate input validation on UNC paths provided in API parameters. When Apache Solr is running in standalone mode, an attacker who can interact with the create core API - either through an unauthenticated endpoint or by leveraging low-privileged credentials - can inject a malicious UNC path. This action triggers an immediate network operation to resolve the path before the application validates the input. Exploitation of this flaw can result in the leakage of NTLM hashes through NTLM authentication relay, unauthorized access to sensitive files, or remote code execution under the context of the Solr service account.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the compromise of the host running the Solr instance, data exfiltration of sensitive configuration files, and lateral movement within the network via captured NTLM credentials. Organizations utilizing Apache Solr in standalone mode with create core API access enabled are at highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Apache Solr instances to version 9.10.1 or later to implement proper UNC path validation.\u003c/li\u003e\n\u003cli\u003eAudit access to the Solr create core API; restrict access to authorized management IPs only.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to the 'create core' API containing UNC path patterns (e.g., \\server\\share).\u003c/li\u003e\n\u003cli\u003eReview network egress telemetry for unusual SMB or NTLM authentication traffic originating from Apache Solr servers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T04:37:57Z","date_published":"2026-09-02T04:37:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-apache-solr-cve-2026-22444/","summary":"A vulnerability in the Apache Solr create core API allows unauthenticated or low-privileged attackers to perform UNC path injection, potentially leading to NTLM hash exposure or remote code execution.","title":"Apache Solr UNC Path Validation Vulnerability (CVE-2026-22444)","url":"https://feed.craftedsignal.io/briefs/2026-09-apache-solr-cve-2026-22444/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:apache:solr:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}