Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
High severity
GitHub Reviewed
Published
Jan 21, 2026
to the GitHub Advisory Database
•
Updated Jan 21, 2026
Package
Affected versions
>= 5.3.0, < 9.10.1
Patched versions
9.10.1
Description
Published by the National Vulnerability Database
Jan 21, 2026
Published to the GitHub Advisory Database
Jan 21, 2026
Reviewed
Jan 21, 2026
Last updated
Jan 21, 2026
Deployments of Apache Solr 5.3.0 through 9.10.0 that rely on Solr's "Rule Based Authorization Plugin" are vulnerable to allowing unauthorized access to certain Solr APIs, due to insufficiently strict input validation in those components. Only deployments that meet all of the following criteria are impacted by this vulnerability:
Users can mitigate this vulnerability by ensuring that their RuleBasedAuthorizationPlugin configuration specifies the "all" pre-defined permission and associates the permission with an "admin" or other privileged role. Users can also upgrade to a Solr version outside of the impacted range, such as the recently released Solr 9.10.1.
References