FAIL › dossier
Solr
PRODUCT· dossier confidence 50%
Apache Solr is an open-source search platform that has suffered multiple high-severity remote code execution vulnerabilities in optional modules and plug-ins, as well as hardcoded credentials in its authentication setup tool.
PROFILE
Categorysearch-engineWhat they doApache Solr is an open-source search platform built on Apache Lucene.
SECURITY POSTURE
Apache Solr has a history of high-severity remote code execution vulnerabilities in optional modules and plug-ins, alongside hardcoded credentials in authentication tools.
Notable failures
- CVE-2019-0193 DataImportHandler RCE
- CVE-2019-17558 VelocityResponseWriter RCE
- CVE-2026-44825 hardcoded credentials
Patterns: repeated RCE in optional modules; hardcoded credentials in auth tools
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-12-10 | CVE-2019-0193 | high | Apache Solr's DataImportHandler module suffered a code injection vulnerability that was actively exploited in the wild. |
| 2021-11-03 | CVE-2019-17558 | high | Apache Solr's VelocityResponseWriter plug-in suffered a remote code execution vulnerability that was actively exploited in the wild. |
| 2026-06-01 | CVE-2026-44825 | high | CVE-2026-44825: Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab |
Open questions: Apache Solr's current patching SLA for optional modules · Whether hardcoded credentials in CVE-2026-44825 were ever remediated
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-16 04:28:36.417993+00:00