Executive brief
A security vulnerability exists in the Apache Lucene.Net.Replicator library, which is used to synchronize search index data between different servers. An attacker could potentially exploit this flaw to access files outside of the intended directory, leading to the exposure of sensitive system information. Organizations using affected versions should update to version 4.8.0-beta00018 to ensure their data remains protected.
Technical details
A path traversal vulnerability (CWE-22) exists in the Apache Lucene.Net.Replicator library. The flaw occurs due to improper validation of pathnames when replicating index files, potentially allowing an attacker to access files outside the restricted directory. The vulnerability affects versions 4.8.0-beta00005 through 4.8.0-beta00017. While the attack vector is network-based, successful exploitation requires specific environmental conditions (AC:H/AT:P). A fix is available in version 4.8.0-beta00018.
Affected products
- Apache Software Foundation Lucene.Net.Replicator 4.8.0-beta00005 to 4.8.0-beta00017
Timeline
- 2026-07-03: advisory: CVE published by Apache Software Foundation
- 2026-07-03: patched: Fix released in version 4.8.0-beta00018