{"id":2604,"date":"2026-06-07T03:45:27","date_gmt":"2026-06-07T10:45:27","guid":{"rendered":"https:\/\/www.cycognito.com\/blog\/?p=2604"},"modified":"2026-06-07T03:45:29","modified_gmt":"2026-06-07T10:45:29","slug":"emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials","status":"publish","type":"post","link":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/","title":{"rendered":"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">What is CVE-2026-44825?<\/h2>\n\n\n\n<p>CVE-2026-44825 is a hardcoded credentials vulnerability in Apache Solr&#8217;s Basic Authentication setup tool, <code>bin\/solr auth enable<\/code>, that can silently install undocumented template accounts with publicly known default credentials, giving a remote attacker full administrative access to the SolrCloud cluster. The vulnerability carries a CVSS v3.1 base score of 8.1 (High).<\/p>\n\n\n\n<p>Exploitation requires no prior authentication. When an administrator uses <code>bin\/solr auth enable<\/code> to configure BasicAuth, the tool writes a <code>security.json<\/code> file that may include additional template user accounts, including accounts named <code>superadmin<\/code>, <code>admin<\/code>, <code>search<\/code>, and <code>index<\/code>, each configured with a password that matches the username. Because the credentials are identical to documented defaults, any attacker aware of the issue can attempt authentication with no additional reconnaissance.<\/p>\n\n\n\n<p>The practical impact is full administrative control of the cluster. An attacker who authenticates as <code>superadmin<\/code> can read, modify, or delete any index, alter cluster configuration, and pivot to any system the Solr cluster is authorized to reach.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What assets are affected by CVE-2026-44825?<\/h2>\n\n\n\n<p>Apache Solr versions 9.4.0 through 9.10.1 and version 10.0.0 are affected. The vulnerability is specific to SolrCloud deployments where administrators have enabled Basic Authentication using <code>bin\/solr auth enable<\/code>. Deployments that configured BasicAuth through other means, or that never enabled BasicAuth at all, are not affected by this specific issue.<\/p>\n\n\n\n<p>Apache Solr powers enterprise search, e-commerce product catalogs, log analytics pipelines, and document management platforms across a wide range of industries. SolrCloud clusters are commonly internet-facing or reachable from cloud environments, and administrative interfaces are often left accessible beyond the intended perimeter during initial setup or after infrastructure changes.<\/p>\n\n\n\n<p>The silent installation of template accounts compounds the risk: administrators who verify their own account credentials after setup have no obvious reason to check for additional accounts they did not create. The template users may persist for extended periods without detection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What does our data show about exposure patterns?<\/h2>\n\n\n\n<p>Using the CyCognito platform, we identified externally reachable Apache Solr assets that may be exposed to this issue across a range of industries. Because no asset file was provided for this advisory, per-sector percentages are not available for this post.<\/p>\n\n\n\n<p>The nature of Apache Solr deployments, widely adopted across data-heavy industries including retail, media, financial services, and enterprise IT, suggests that exposure is broadly distributed rather than concentrated in a single sector. Organizations running Solr as part of search or analytics infrastructure often inherit the software through platform bundles or third-party applications, which can delay visibility into version currency and authentication state.<\/p>\n\n\n\n<p>Cross-sector deployments of this kind also tend to accumulate transitional infrastructure: Solr clusters stood up for a specific application and never decommissioned, or upgraded to a new version in production while older instances remain accessible in staging or development environments.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are fixes available?<\/h2>\n\n\n\n<p>Patches are available. Apache has released Solr 9.11.0 and 10.1.0 to address CVE-2026-44825. Organizations running any version from 9.4.0 through 9.10.1, or version 10.0.0, should upgrade to the respective fixed release.<\/p>\n\n\n\n<p>For deployments where an immediate upgrade is not possible, Apache recommends deleting the template accounts created by <code>bin\/solr auth enable<\/code>. The accounts to audit and remove are <code>superadmin<\/code>, <code>admin<\/code>, <code>search<\/code>, and <code>index<\/code>. These accounts are defined in <code>security.json<\/code> and can be removed or have their credentials rotated through the Solr Security API.<\/p>\n\n\n\n<p>Defenders should verify directly with Apache&#8217;s security advisory and their deployment&#8217;s <code>security.json<\/code> contents rather than assuming a prior authentication review was comprehensive. The absence of self-created accounts with weak credentials does not rule out the presence of silently installed template accounts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Are there any other recommended actions to take?<\/h2>\n\n\n\n<p>Until patching is confirmed, defenders should:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Audit <code>security.json<\/code> on all SolrCloud nodes for undocumented template accounts<\/li>\n\n\n\n<li>Remove or rotate credentials for <code>superadmin<\/code>, <code>admin<\/code>, <code>search<\/code>, and <code>index<\/code> if present<\/li>\n\n\n\n<li>Restrict network access to the Solr admin interface at the firewall or WAF layer<\/li>\n\n\n\n<li>Monitor Solr authentication logs for logins using default credential patterns<\/li>\n\n\n\n<li>Inventory all Solr deployments, including staging and development instances, to identify versions in the affected range<\/li>\n\n\n\n<li>Verify that BasicAuth-enabled clusters were not configured using <code>bin\/solr auth enable<\/code> on any affected version<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">How can CyCognito help your organization?<\/h2>\n\n\n\n<p>CyCognito published an Emerging Threat Advisory for CVE-2026-44825 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.<\/p>\n\n\n\n<p>To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, <a href=\"https:\/\/www.cycognito.com\/demo\/\">contact us to request a demo<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A hardcoded credentials flaw in Apache Solr&#8217;s Basic Authentication setup tool silently installs undocumented admin accounts with default passwords, giving remote attackers full control of affected SolrCloud clusters.<\/p>\n","protected":false},"author":39,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[250],"tags":[],"class_list":["post-2604","post","type-post","status-publish","format-standard","hentry","category-emerging-threats"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials | CyCognito Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials | CyCognito Blog\" \/>\n<meta property=\"og:description\" content=\"A hardcoded credentials flaw in Apache Solr&#039;s Basic Authentication setup tool silently installs undocumented admin accounts with default passwords, giving remote attackers full control of affected SolrCloud clusters.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/\" \/>\n<meta property=\"og:site_name\" content=\"CyCognito Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-07T10:45:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-07T10:45:29+00:00\" \/>\n<meta name=\"author\" content=\"Igal Zeifman\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Igal Zeifman\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/\"},\"author\":{\"name\":\"Igal Zeifman\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3\"},\"headline\":\"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials\",\"datePublished\":\"2026-06-07T10:45:27+00:00\",\"dateModified\":\"2026-06-07T10:45:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/\"},\"wordCount\":699,\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"articleSection\":[\"Emerging Threats\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/\",\"name\":\"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials | CyCognito Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\"},\"datePublished\":\"2026-06-07T10:45:27+00:00\",\"dateModified\":\"2026-06-07T10:45:29+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cycognito.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#website\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"name\":\"Cycognito Blog\",\"description\":\"Research, Product News and Latest Updates\",\"publisher\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#organization\",\"name\":\"Cycognito\",\"url\":\"https:\/\/www.cycognito.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"contentUrl\":\"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png\",\"width\":1720,\"height\":550,\"caption\":\"Cycognito\"},\"image\":{\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3\",\"name\":\"Igal Zeifman\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g\",\"caption\":\"Igal Zeifman\"},\"description\":\"VP of Marketing\",\"url\":\"https:\/\/www.cycognito.com\/blog\/author\/igal-zeifman\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials | CyCognito Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/","og_locale":"en_US","og_type":"article","og_title":"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials | CyCognito Blog","og_description":"A hardcoded credentials flaw in Apache Solr's Basic Authentication setup tool silently installs undocumented admin accounts with default passwords, giving remote attackers full control of affected SolrCloud clusters.","og_url":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/","og_site_name":"CyCognito Blog","article_published_time":"2026-06-07T10:45:27+00:00","article_modified_time":"2026-06-07T10:45:29+00:00","author":"Igal Zeifman","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Igal Zeifman","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/#article","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/"},"author":{"name":"Igal Zeifman","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3"},"headline":"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials","datePublished":"2026-06-07T10:45:27+00:00","dateModified":"2026-06-07T10:45:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/"},"wordCount":699,"publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"articleSection":["Emerging Threats"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/","url":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/","name":"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials | CyCognito Blog","isPartOf":{"@id":"https:\/\/www.cycognito.com\/blog\/#website"},"datePublished":"2026-06-07T10:45:27+00:00","dateModified":"2026-06-07T10:45:29+00:00","breadcrumb":{"@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.cycognito.com\/blog\/emerging-threat-cve-2026-44825-apache-solr-administrative-takeover-via-hardcoded-credentials\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cycognito.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Emerging Threat: (CVE-2026-44825) Apache Solr Administrative Takeover via Hardcoded Credentials"}]},{"@type":"WebSite","@id":"https:\/\/www.cycognito.com\/blog\/#website","url":"https:\/\/www.cycognito.com\/blog\/","name":"Cycognito Blog","description":"Research, Product News and Latest Updates","publisher":{"@id":"https:\/\/www.cycognito.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cycognito.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.cycognito.com\/blog\/#organization","name":"Cycognito","url":"https:\/\/www.cycognito.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","contentUrl":"https:\/\/www.cycognito.com\/blog\/wp-content\/uploads\/logo-1720x550-1.png","width":1720,"height":550,"caption":"Cycognito"},"image":{"@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/79ab10bc35a38aef399f5bbd21d8f1b3","name":"Igal Zeifman","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cycognito.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b4495bcfbe7465d573c6f7ee3e2a3cab?s=96&d=mm&r=g","caption":"Igal Zeifman"},"description":"VP of Marketing","url":"https:\/\/www.cycognito.com\/blog\/author\/igal-zeifman\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/comments?post=2604"}],"version-history":[{"count":1,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2604\/revisions"}],"predecessor-version":[{"id":2605,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/posts\/2604\/revisions\/2605"}],"wp:attachment":[{"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/media?parent=2604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/categories?post=2604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cycognito.com\/blog\/wp-json\/wp\/v2\/tags?post=2604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}