Unknown · Lucene.Net.Replicator · CVE-2026-47897
**Name of the Vulnerable Software and Affected Versions**
Apache Lucene.Net.Replicator versions 4.8.0-beta00005 through 4.8.0-beta00017
**Description**
A path traversal issue exists in the Lucene.Net.Replicator library due to improper input validation and sanitization of filesystem paths. This allows traversal sequences to escape the intended base path, potentially enabling unauthorized read or write access to files outside the replication directories. This can lead to the leakage of sensitive data, tampering with replicated index artifacts, or service compromise if an attacker can supply crafted path values to replication-related APIs or endpoints that pass user-controlled input into file operations.
**Recommendations**
Upgrade to version 4.8.0-beta00018.