Data Exposure Vulnerability in Metacat Data Repository Software by NCEAS
CVE-2026-50022
5.8MEDIUM
What is CVE-2026-50022?
Metacat, a data repository solution designed for researchers, had a vulnerability in its Solr search implementation before version 3.4.2. An unauthenticated user could exploit the MetacatSolrIndex.query feature, manipulating the client-controlled qt parameter. This manipulation allowed for the retrieval of sensitive configuration files from the Solr backend, even when security settings were in place to prevent such access. This flaw could lead to unauthorized exposure of internal files, posing a significant risk to the system's integrity. The issue has been addressed in version 3.4.2, mitigating the risk of data leakage.
Affected Version(s)
metacat < 3.4.2
