CVE-2026-50022: Metacat acts as unintended proxy to backend Apache SOLR engine

Published Sep 17, 2026
·
Updated

Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ from search endpoints such as /d1/mn/v2/query/solr/ to its privileged Solr backend. An unauthenticated client can select the /admin/file handler, and SolrJ reformats the parameter into a request accepted even when handleSelect=false is configured on Solr 7.0 or later. When Solr returns the selected core configuration file, Metacat embeds the raw content in an XML processing error response, disclosing internal files such as solrconfig.xml and enabling infrastructure profiling. This issue is fixed in version 3.4.2.

Affected Software

2 affected components
Metacat Metacat<3.4.2
Apache Solr<=7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Metacat to a version that resolves this vulnerability.

    Fixed in 3.4.2

Event History

Sep 17, 2026
CVE Published
via MITRE·08:06 PM
Data Sourced
via MITRE·08:06 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated disclosure?

Metacat versions before 3.4.2 with reachable search endpoints such as /d1/mn/v2/query/solr/ are exposed. No authentication is required for an attacker to send the controlled query parameter.

2

Does disabling Solr's select handler prevent this issue?

No. On Solr 7.0 or later, the request is reformatted by SolrJ and accepted even when handleSelect=false is configured.

3

What information can be disclosed?

An attacker can select Solr's /admin/file handler and cause returned core configuration content to be included raw in an XML processing error response. This can disclose files such as solrconfig.xml and support profiling of internal infrastructure.

4

What is the remediation?

Upgrade Metacat to version 3.4.2, which fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203