Apache disclosed CVE-2026-44825, a high-severity flaw in Apache Solr’s Basic Authentication bootstrap process that can leave clusters open to full remote administrative takeover. In affected versions, running the BasicAuth setup command
bin/solr auth enable
silently creates additional template accounts with publicly known default credentials alongside the administrator account chosen by the operator.
The issue affects Solr 9.4.0 through 9.10.1 and 10.0.0 and is tracked as SOLR-18233. Apache said deployments are at risk if they used the CLI to enable BasicAuth and left the template users unchanged; the exposed accounts include superadmin, admin, search, and index in security.json. As an immediate mitigation, administrators should remove those users or assign strong passwords, while fixes are expected in 9.11.0 and 10.1.0. The vulnerability was reported by Naveen Sunkavally of Horizon3.ai.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
Apache disclosed CVE-2026-44825, a high-severity hardcoded-credentials vulnerability in Apache Solr's Basic Authentication setup tool. The issue affects Solr 9.4.0 through 9.10.1 and 10.0.0 when `bin/solr auth enable` creates additional template users with publicly known credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcehorizon3.ai
Open sourcecvefeed.io
Open sourceopenwall.com
Open sourceseclists.org
Open sourcelists.apache.org
Open sourceissues.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.