https://seclists.org/oss-sec/2026/q1/91: CVE-2026-22022: Apache Solr: Unauthorized bypass of certain "pdefined permission" rules in the RuleBasedAuthorizationPlugin
Published Jan 20, 2026
·Updated
Affected Software
1 affected component
Apache Solr>=5.3<=9.10.0
Frequently Asked Questions
1
What is the severity of CVE-2026-22022?
The severity of CVE-2026-22022 is classified as moderate.
2
What versions of Apache Solr are affected by CVE-2026-22022?
Apache Solr versions from 5.3.0 through 9.10.0 are affected by CVE-2026-22022.
3
How do I fix CVE-2026-22022?
To fix CVE-2026-22022, upgrade Apache Solr to a version later than 9.10.0 that addresses the vulnerability.
4
What does CVE-2026-22022 affect in Apache Solr?
CVE-2026-22022 affects the Rule Based Authorization Plugin, allowing unauthorized access to certain Solr APIs.
5
What is the cause of CVE-2026-22022?
CVE-2026-22022 is caused by insufficiently strict input validation in the RuleBasedAuthorizationPlugin.