PT-2026-95085 · Metacart+1 · Metacart+1

CVE-2026-50022

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

5.8

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Metacat versions prior to 3.4.2
Description Metacat is data repository software used for preserving, sharing, and discovering data. The MetacatSolrIndex.query function forwards the client-controlled qt parameter through Apache SolrJ from search endpoints, such as '/d1/mn/v2/query/solr/', to a privileged Solr backend. An unauthenticated client can select the '/admin/file' handler, which SolrJ reformats into a request that is accepted even if handleSelect=false is configured on Solr 7.0 or later. This allows the disclosure of internal files, such as solrconfig.xml, as Metacat embeds the raw content in an XML processing error response, facilitating infrastructure profiling.
Recommendations Update to version 3.4.2.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50022
GHSA-57G5-QQ6W-7JR8

Affected Products

Apache Solr
Metacart