Server Online
Server Online

Advisory 2026-10/01 Authentication Bypass Vulnerability

Security Advisory 

CVE-2026-75595 — io.netty:netty-handler 

Severity 

Critical 

Affected Component 

Solr (bundled with FileCloud) 

Status 

Fix available — manual remediation required 

Versions affected

FileCloud versions 23.232 through 23.262.2.34016

Version fixed

FileCloud version 23.263 and later

Summary 

A critical vulnerability, CVE-2026-75595, has been identified in io.netty:netty-handler (versions prior to 4.2.17.Final), which is bundled as a dependency within the Solr search component shipped with FileCloud. This library is used to support OpenTelemetry instrumentation and Zookeeper/SolrCloud networking functions within Solr. 

FileCloud's product security team has verified that these components are not required for core FileCloud functionality — including setup, indexing, reindexing, and search (with and without OCR). Customers are advised to remove the affected JAR files and restart Solr as described below. 

Affected Versions / Scope 

  • Solr version: 9.10.1 (as bundled with FileCloud) 

  • Affected package: io.netty:netty-handler 4.2.6.Final and related dependent JARs 

Impact 

The vulnerable Netty components are used by: 

  • OpenTelemetry (observability/tracing module) 

  • Zookeeper / SolrCloud networking 

They are not used by core Solr indexing, search, or FileCloud document processing paths, so removal does not affect normal FileCloud operation. 


What you should do to fix this vulnerability

FileCloud Server admins:

If you are performing a new installation of FileCloud, this issue will be fixed for you.

If you are not performing a new installation of FileCloud, do the following to fix this issue:

To fix this issue

Remove the following JAR files manually, then restart Solr. 

File paths 

  • Linux: /opt/solr-9.10.1/ 

  • Windows: XAMPP/solr/ 

Files to remove 

server/solr-webapp/webapp/WEB-INF/lib/  (11 files) 

  • netty-handler-4.2.6.Final.jar 

  • netty-buffer-4.2.6.Final.jar 

  • netty-codec-base-4.2.6.Final.jar 

  • netty-common-4.2.6.Final.jar 

  • netty-resolver-4.2.6.Final.jar 

  • netty-transport-4.2.6.Final.jar 

  • netty-transport-classes-epoll-4.2.6.Final.jar 

  • netty-transport-native-epoll-4.2.6.Final-linux-x86_64.jar 

  • netty-transport-native-unix-common-4.2.6.Final.jar 

  • netty-tcnative-boringssl-static-2.0.73.Final.jar 

  • netty-tcnative-classes-2.0.73.Final.jar 

modules/opentelemetry/lib/  (6 files) 

  • grpc-netty-1.65.1.jar 

  • netty-codec-http-4.2.6.Final.jar 

  • netty-codec-http2-4.2.6.Final.jar 

  • netty-codec-socks-4.2.6.Final.jar 

  • netty-codec-compression-4.2.6.Final.jar 

  • netty-handler-proxy-4.2.6.Final.jar 

modules/gcs-repository/lib/  (1 file) 

  • grpc-netty-shaded-1.65.1.jar 

Steps 

  1. Stop the Solr service. 

  1. Navigate to the appropriate path for your OS (Linux: /opt/solr-9.10.1/; Windows: XAMPP/solr/). 

  1. Delete the 18 files listed above from their respective directories. 

  1. Restart the Solr service. 

  1. Verify Solr starts cleanly and that indexing/search functions as expected. 

Notes / Caveats 

  • Removing these files disables OpenTelemetry instrumentation and Zookeeper/SolrCloud-related Netty networking within Solr. If your deployment relies on SolrCloud clustering, review with your account team before proceeding. 

  • This has been verified on Windows to not impact FileCloud setup, indexing, reindexing, or search (with and without OCR). 

References 

FileCloud Online Admins

This issue will be fixed for you when the latest version of FileCloud is released on October 10-11, 2026.



If you have any questions about this advisory, please contact FileCloud support.