Skip to content
COOEY

FAIL › dossier

Solr

PRODUCT

· dossier confidence 50%

Apache Solr is an open-source search platform that has suffered multiple high-severity remote code execution vulnerabilities in optional modules and plug-ins, as well as hardcoded credentials in its authentication setup tool.

PROFILE
Categorysearch-engineWhat they doApache Solr is an open-source search platform built on Apache Lucene.
SECURITY POSTURE

Apache Solr has a history of high-severity remote code execution vulnerabilities in optional modules and plug-ins, alongside hardcoded credentials in authentication tools.

Notable failures
  • CVE-2019-0193 DataImportHandler RCE
  • CVE-2019-17558 VelocityResponseWriter RCE
  • CVE-2026-44825 hardcoded credentials
Patterns: repeated RCE in optional modules; hardcoded credentials in auth tools
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2021-12-10 CVE-2019-0193 high Apache Solr's DataImportHandler module suffered a code injection vulnerability that was actively exploited in the wild.
2021-11-03 CVE-2019-17558 high Apache Solr's VelocityResponseWriter plug-in suffered a remote code execution vulnerability that was actively exploited in the wild.
2026-06-01 CVE-2026-44825 high CVE-2026-44825: Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab
Open questions: Apache Solr's current patching SLA for optional modules · Whether hardcoded credentials in CVE-2026-44825 were ever remediated
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-16 04:28:36.417993+00:00