CVE-2026-45083 Details
Description
The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unauthenticated network clients and forwarded it to the backend Solr server without restriction. An attacker could read the complete Solr index and, in default Solr deployments, also modify or delete indexed records. This vulnerability is fixed in 26.04.1.
A critical vulnerability exists in the Goobi Viewer REST endpoint POST /api/v1/index/stream, in versions 4.8.0 prior to 26.04.1. This endpoint accepted arbitrary Solr streaming expressions from unauthenticated network clients and forwarded them to the backend Solr server without any restrictions. As a result, an attacker could read the entire Solr index and, in default Solr deployments, also modify or delete indexed records. The vulnerability has been addressed by removing the endpoint altogether.
Users are advised to update to Goobi Viewer version 26.04.1 or later. If an immediate update is not possible, the endpoint can be blocked using a reverse proxy or by modifying the Tomcat configuration to deny access to the /api/v1/index/stream endpoint.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 27, 2026CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Intranda Goobi viewer | >= 4.8.0, < 26.04.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | New CVE Received | [email protected] |
Volerion