---
schema: 1
kind: vulnerability
title: "CVE-2026-44825 — Apache Solr: unauthenticated admin via hardcoded template credentials, no patch yet"
headline: "CVE-2026-44825 — Apache Solr: unauthenticated admin via hardcoded template credentials, no patch yet"
summary: "CVE-2026-44825 (CVSS 8.1, CWE-798/1188) stems from Apache Solr's bin/solr auth enable BasicAuth bootstrap tool, which provisions fixed template accounts (superadmin, admin, search, index) with well-known default credentials in security.json and does not remove or randomise them after setup (BSI CERT-Bund …"
discovered_at: "2026-06-02T05:00:06Z"
event_date: 2026-06-01
run_id: 2026-06-02-8af85d01
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - auth-bypass
  - pre-auth
  - no-patch
  - default-config
regions:
  - global
sectors:
  - public-sector
  - education
  - legal-services
entities: []
cves:
  - id: CVE-2026-44825
    cvss: "8.1"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: default-config
    status:
      - no-patch
      - mitigation-only
sources:
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1740"
    publisher: BSI CERT-Bund WID-SEC-2026-1740
    role: primary
  - url: "https://cve.threatint.eu/CVE/CVE-2026-44825"
    publisher: THREATINT CVE record
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-02.md
---

CVE-2026-44825 (CVSS 8.1, CWE-798/1188) stems from Apache Solr's `bin/solr auth enable` BasicAuth bootstrap tool, which provisions fixed template accounts (`superadmin`, `admin`, `search`, `index`) with well-known default credentials in `security.json` and does not remove or randomise them after setup ([BSI CERT-Bund WID-SEC-2026-1740, 2026-06-01](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1740) · [THREATINT, 2026-06-01](https://cve.threatint.eu/CVE/CVE-2026-44825)). An unauthenticated attacker reaching the Solr REST API (HTTP/8983 by default) can authenticate with those credentials and take full administrative control of the cluster — reading every core/collection, altering configsets, and pivoting to server-side script execution. Affected: 9.4.0–9.10.1 and 10.0.0; fixed builds (9.11.0 / 10.1.0) are not yet released, so the workaround is mandatory now: delete the four template users from `security.json` or rotate their passwords. Deployments that never ran `bin/solr auth enable`, or rotated template passwords immediately, are unaffected. Reported by Naveen Sunkavally (Horizon3.ai) via Apache's oss-security list.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-8732 | WP Maps Pro WordPress plugin ≤ 6.1.0 | 9.8 | n/a | No | Yes | 6.1.1 | [BleepingComputer](https://www.bleepingcomputer.com/news/security/wp-maps-pro-bug-exploited-to-create-admin-accounts-on-wordpress-sites/) |
| CVE-2026-8931 | Disig Web Signer 2.0.3–2.5.3 (eIDAS client) | 9.4 | n/a | No | No | 2.5.5 | [Disig](https://www.disig.sk/en/news/important-update-of-the-web-signer-application/) |
| CVE-2026-44825 | Apache Solr 9.4.0–9.10.1, 10.0.0 | 8.1 | n/a | No | No | None yet (workaround) | [BSI CERT-Bund](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1740) |
| CVE-2026-41089 | Windows Netlogon (all supported Server) | 9.8 | n/a | No | Yes | May 2026 PT | [BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/) |

*CVE-2026-41089 is treated as a §4 update (active exploitation of a previously-covered May Patch Tuesday fix);*
