https://seclists.org/oss-sec/2026/q1/92: CVE-2026-22444: Apache Solr: Insufficient file-access checking in standalone co-cation quests
Published Jan 20, 2026
·Updated
Affected Software
1 affected component
Apache Solr>=8.6<9.10.0
Frequently Asked Questions
1
What is the severity of CVE-2026-22444?
The severity of CVE-2026-22444 is classified as moderate.
2
What versions of Apache Solr are affected by CVE-2026-22444?
Apache Solr versions 8.6 through 9.10.0 are affected by CVE-2026-22444.
3
How do I fix CVE-2026-22444?
To fix CVE-2026-22444, upgrade to a version of Apache Solr that is not affected, specifically above 9.10.0.
4
What vulnerability does CVE-2026-22444 address?
CVE-2026-22444 addresses insufficient file-access checking in the 'create core' API of Apache Solr.
5
Can CVE-2026-22444 lead to security risks?
Yes, CVE-2026-22444 can lead to unauthorized access to file-system paths due to inadequate input validation.