Data Exposure Vulnerability in Metacat Data Repository Software by NCEAS
CVE-2026-50022

5.8MEDIUM

Key Information:

Vendor

Nceas

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-50022?

Metacat, a data repository solution designed for researchers, had a vulnerability in its Solr search implementation before version 3.4.2. An unauthenticated user could exploit the MetacatSolrIndex.query feature, manipulating the client-controlled qt parameter. This manipulation allowed for the retrieval of sensitive configuration files from the Solr backend, even when security settings were in place to prevent such access. This flaw could lead to unauthorized exposure of internal files, posing a significant risk to the system's integrity. The issue has been addressed in version 3.4.2, mitigating the risk of data leakage.

Affected Version(s)

metacat < 3.4.2

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.