Skip to content

CVE-2026-44825

WSO2 Products impacted: no

Customer action required: no


REPORTED VULNERABILITY

Hardcoded credentials in Apache Solr's Basic Authentication setup tool (bin/solr auth enable) allow a remote attacker to gain full administrative access to a Solr cluster via publicly known default credentials installed silently alongside the user-specified account, in Solr versions 9.4.0 through 9.10.1 and 10.0.0 1.

REPORTED PRODUCTS

  • WSO2 API Manager : 4.6.0

WSO2 JUSTIFICATION

solr-core is included transitively through the Apache Solr bundle, which supports Governance Registry content indexing in the product. The CVE-2026-44825 vulnerability is exploitable only when a Solr cluster's Basic Authentication has been bootstrapped via the bin/solr auth enable command-line setup tool, and only when that cluster's HTTP API is reachable over the network by an attacker. A thorough analysis of all Solr-related code paths in WSO2 API Manager confirms that neither precondition is ever met:

Embedded Solr mode: WSO2 API Manager does not run Solr as a standalone server process; it embeds Solr in-process via the EmbeddedSolrServer API (confirmed in the product's own startup log: "Default Embedded Solr Server Initialized"). Communication with Solr happens through direct in-process Java method calls, not over HTTP.

bin/solr setup tooling is never invoked: While the AuthTool/SolrCLI classes that implement bin/solr auth enable are present in the bundled solr-core jar, WSO2 API Manager never invokes this command-line setup path. No template users or their default credentials are ever provisioned by the product.

No network-exposed Solr endpoint: A full listing of the running product's listening TCP ports confirms there is no network-exposed Solr HTTP API at all, independent of the point above.

This matches the upstream advisory's own stated non-affected condition: "Not affected: Clusters where bin/solr auth enable was not used to bootstrap BasicAuth" 1.

In addition, there is currently no fixed Solr release available among the 9.x versions included in the WSO2 products.

CONCLUSION

  • WSO2 API Manager embeds Solr in-process and never invokes the bin/solr auth enable setup tooling that this vulnerability depends on, and exposes no network-reachable Solr endpoint.

Therefore, WSO2 concludes that this vulnerability does not pose a security risk to the impacted version of WSO2 API Manager listed above.

REFERENCES