PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Exposed Panels·Updated Aug 2, 2026

Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-44825
8.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. As an immediate workaround without upgrading, delete the template users (superadmin, admin, search, index) from security.json or change their passwords. The future, not yet released, versions 9.11.0 and 10.1.0 will not be vulnerable, and it will be enough to upgrade to solve the issue. Not affected: * Clusters where bin/solr auth enable was not used to bootstrap BasicAuth * Clusters where template users have been assigned strong passwords after bootstrap

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Solrby Apache Software Foundation
9.4.0
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials CVE-2026-44825 Scanner | S4E