References https://www.cnblogs.com/null1433/p/12723729.html https://www.anquanke.com/post/id/193208 https://github.com/hktalent/MyDocs/blob/main/Apache%20Solr%20JMX%E6%9C%8D%E5%8A%A1%20RCE%20CVE-2019-12409.md https://blog.csdn.net/ll_515/article/details/128739785 https://cloud.tencent.com/developer/article/1541836 https://www.tenablecloud.cn/plugins/nessus/132315 https://blog.nsfocus.net/cve-2019-12409/ https://avd.aliyun.com/detail?id=AVD-2019-12409 https://wiki.96.mk/Web%E5%AE%89%E5%85%A8/Apache%20Solr/%EF%BC%88CVE-2019-12409%EF%BC%89Apache%20Solr%20%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E/ https://www.cnblogs.com/Sylon/p/11927518.html https://nvd.nist.gov/vuln/detail/CVE-2019-12409 https://www.rapid7.com/db/vulnerabilities/apache-solr-cve-2019-12409/ https://github.com/jas502n/CVE-2019-12409 https://issues.apache.org/jira/browse/SOLR-13647 https://www.tenable.com/cve/CVE-2019-12409
Related VulnerabilitiesPoCCVE-2022-27925: Zimbra Collaboration Suite 8.8.15/9.0 - Zip Path TraversalPoCCVE-2026-10818: WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File UploadPoCCVE-2026-21589: Atlassian Jira/Confluence/Bitbucket - Pre-Auth Arbitrary File ReadPoCCVE-2026-26216: Crawl4AI < 0.8.0 - Unauthenticated Remote Code Execution via Hooks ParameterPoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoCCVE-2026-40281: Gotenberg <= 8.30.1 - Remote Code ExecutionPoCCVE-2026-49468: LiteLLM Proxy < 1.84.0 - Host Header Authentication BypassPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCApache Cocoon /xmlui/themes/Mirage2 目录遍历漏洞QAnything /api/local_doc_qa/upload_files 文件上传漏洞(CVE-2026-88533)Apache Kafka UI /smartfilters/testexecutions 代码执行漏洞(CVE-2026-78166)PoCCVE-2024-57728: SimpleHelp <= 5.5.7 - Arbitrary File UploadPoCCVE-2025-68273: Signal K Server <= 2.18.0 - Information Disclosure