← Vulnerability feed

Vulnerability record · CVE-2024-45216 · published 16 October 2024

CVE-2024-45216: Apache Solr PKIAuthenticationPlugin authentication bypass via fake URL path ending

Apache · Solr

Apache Solr instances using the PKIAuthenticationPlugin, enabled by default when Solr Authentication is used, can be bypassed by appending a fake path ending to any Solr API URL. The fake ending is stripped internally after authentication but before API routing, so requests skip authentication while still reaching the intended API path. This affects Solr 5.3.0 before 8.11.4 and 9.0.0 before 9.7.0.

9.8 CVSS 3.1 Critical EPSS 93% · top 0.2% CWE-287 · Improper authenticationCWE-863 · Incorrect authorization
9.8CVSS 3.1 base score
93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper Authentication vulnerability in Apache Solr. Solr instances using the PKIAuthenticationPlugin, which is enabled by default when Solr Authentication is used, are vulnerable to Authentication bypass. A fake ending at the end of any Solr API URL path, will allow requests to skip Authentication while maintaining the API contract with the original URL Path. This fake ending looks like an unprotected API path, however it is stripped off internally after authentication but before API routing. This issue affects Apache Solr: from 5.3.0 before 8.11.4, from 9.0.0 before 9.7.0. Users are recommended to upgrade to version 9.7.0, or 8.11.4, which fix the issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, default-enabled vulnerable component, and very high EPSS probability make this an urgent patch.

What it is

Apache Solr instances using the PKIAuthenticationPlugin, enabled by default when Solr Authentication is used, can be bypassed by appending a fake path ending to any Solr API URL. The fake ending is stripped internally after authentication but before API routing, so requests skip authentication while still reaching the intended API path. This affects Solr 5.3.0 before 8.11.4 and 9.0.0 before 9.7.0.

Impact

An unauthenticated attacker can reach Solr APIs that should require authentication, gaining full read and write access to indexed data and administrative functionality. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reachable over the network via HTTP requests to the Solr API; no authentication is required because the flaw itself bypasses authentication, and no user interaction is needed. Any Solr instance with authentication enabled and the default PKIAuthenticationPlugin is exposed.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.917 (99.8th percentile), indicating likely active exploitation interest. References are limited to the vendor advisory and an oss-security mailing list post, with no public exploit tag.

What to do

  • Upgrade Apache Solr to 9.7.0 or 8.11.4, which fix the issue.
  • If immediate upgrade is not possible, restrict network access to Solr API ports to trusted hosts only.
  • Verify that Solr authentication is actually enforced by testing a request with a fake path ending against a protected endpoint.
  • Review Solr access logs for requests containing suspicious trailing path segments that do not match known API routes.

Detection

  • Search Solr request logs for API paths with unexpected trailing segments that are not valid Solr endpoints.
  • Alert on successful responses to protected Solr API paths from clients that did not present authentication credentials.
  • Monitor for anomalous administrative API calls, such as config or collection changes, originating from unauthenticated or unexpected sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-45216 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2019-17558Apache Solr VelocityResponseWriter template injection enables remote code executionApache Solr 5.0.0 through 8.3.1 renders Velocity templates through VelocityResponseWriter, and attacker-supplied templates can execute code. Paramete…KEVEPSS 99%analysed7.2CVE-2019-0193Apache Solr DataImportHandler dataConfig parameter code injectionApache Solr's DataImportHandler accepts a full DIH configuration through the request's dataConfig parameter, and because a DIH config can contain scr…KEVEPSS 84%analysed9.8CVE-2026-44825Apache solr hard-coded credentials vulnerabilityHardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a …EPSS 2.8%9.8CVE-2021-44548Apache solr improper input validation vulnerabilityAn Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB n…EPSS 5.1%9.8CVE-2021-27905Apache Solr ReplicationHandler masterUrl SSRF flawApache Solr's ReplicationHandler, normally exposed at /replication under a Solr core, accepts a masterUrl (leaderUrl) parameter without validating it…EPSS 93%analysed9.8CVE-2020-13957Apache Solr ConfigSet upload authorization bypass enabling RCEApache Solr versions 6.6.0 to 6.6.6, 7.0.0 to 7.7.3 and 8.0.0 to 8.6.2 block dangerous ConfigSet features that could lead to remote code execution wh…EPSS 79%analysed9.8CVE-2019-12409Apache solr unrestricted file upload vulnerabilityThe 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh…EPSS 21%

Source: NIST National Vulnerability Database (record CVE-2024-45216), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.