Junglewise Threat Intelligence

CVE-2026-47898: Apache Lucene.Net XXE in Lucene.Net.Analysis.Common

CVE-2026-47898 · Severity: info · CVSS 2.1 · Published 2026-07-03

Vendors: Apache Software Foundation.

Executive brief

Apache Lucene.Net is a high-performance search engine library used by .NET applications to provide search and indexing capabilities. A security flaw in how the library processes XML data could allow an attacker with high-level access to the local system to read sensitive files or cause minor service disruptions. Organizations using affected versions should update to the latest beta release to ensure their search infrastructure remains secure.

Technical details

An XML External Entity (XXE) vulnerability exists in the Apache Lucene.Net.Analysis.Common library due to improper restriction of XML external entity references. The root cause is likely the use of an insecurely configured XML parser that allows the resolution of external entities within XML-based analysis configurations. An attacker with local access and high privileges could exploit this to perform server-side request forgery (SSRF) or read local files, though the CVSS 4.0 score suggests significant environmental constraints (AC:H). The issue affects versions 4.8.0-beta00005 through 4.8.0-beta00017 and is resolved in version 4.8.0-beta00018.

Affected products

  • Apache Software Foundation Lucene.Net.Analysis.Common 4.8.0-beta00005 to 4.8.0-beta00017

Timeline

  • 2026-07-03: advisory: Initial disclosure by Apache Software Foundation
  • 2026-07-03: patched: Fix released in version 4.8.0-beta00018

References