๐Ÿ” CVE Alert

CVE-2026-50022

MEDIUM 5.8

Metacat acts as unintended proxy to backend Apache SOLR engine

CVSS Score
5.8
EPSS Score
0.0%
EPSS Percentile
0th

Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ from search endpoints such as /d1/mn/v2/query/solr/ to its privileged Solr backend. An unauthenticated client can select the /admin/file handler, and SolrJ reformats the parameter into a request accepted even when handleSelect=false is configured on Solr 7.0 or later. When Solr returns the selected core configuration file, Metacat embeds the raw content in an XML processing error response, disclosing internal files such as solrconfig.xml and enabling infrastructure profiling. This issue is fixed in version 3.4.2.

CWE CWE-441
Vendor nceas
Product metacat
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for nceas metacat

Be the first to know when new medium vulnerabilities affecting nceas metacat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

NCEAS / metacat
< 3.4.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/NCEAS/metacat/security/advisories/GHSA-57g5-qq6w-7jr8 github.com: https://github.com/NCEAS/metacat/pull/2319 github.com: https://github.com/NCEAS/metacat/commit/d500306188881d768b93f189bb8ddbf090f3f1ec github.com: https://github.com/NCEAS/metacat/releases/tag/3.4.2