CVE-2026-44825¶
WSO2 Products impacted: no
Customer action required: no
REPORTED VULNERABILITY¶
Hardcoded credentials in Apache Solr's Basic Authentication setup tool (bin/solr auth enable) allow a remote attacker to gain full administrative access to a Solr cluster via publicly known default credentials installed silently alongside the user-specified account, in Solr versions 9.4.0 through 9.10.1 and 10.0.0 1.
REPORTED PRODUCTS¶
- WSO2 API Manager : 4.6.0
WSO2 JUSTIFICATION¶
solr-core is included transitively through the Apache Solr bundle, which supports Governance Registry content indexing in the product. The CVE-2026-44825 vulnerability is exploitable only when a Solr cluster's Basic Authentication has been bootstrapped via the bin/solr auth enable command-line setup tool, and only when that cluster's HTTP API is reachable over the network by an attacker. A thorough analysis of all Solr-related code paths in WSO2 API Manager confirms that neither precondition is ever met:
Embedded Solr mode: WSO2 API Manager does not run Solr as a standalone server process; it embeds Solr in-process via the EmbeddedSolrServer API (confirmed in the product's own startup log: "Default Embedded Solr Server Initialized"). Communication with Solr happens through direct in-process Java method calls, not over HTTP.
bin/solr setup tooling is never invoked: While the AuthTool/SolrCLI classes that implement bin/solr auth enable are present in the bundled solr-core jar, WSO2 API Manager never invokes this command-line setup path. No template users or their default credentials are ever provisioned by the product.
No network-exposed Solr endpoint: A full listing of the running product's listening TCP ports confirms there is no network-exposed Solr HTTP API at all, independent of the point above.
This matches the upstream advisory's own stated non-affected condition: "Not affected: Clusters where bin/solr auth enable was not used to bootstrap BasicAuth" 1.
In addition, there is currently no fixed Solr release available among the 9.x versions included in the WSO2 products.
CONCLUSION¶
- WSO2 API Manager embeds Solr in-process and never invokes the
bin/solr auth enablesetup tooling that this vulnerability depends on, and exposes no network-reachable Solr endpoint.
Therefore, WSO2 concludes that this vulnerability does not pose a security risk to the impacted version of WSO2 API Manager listed above.