top of page
perceptive_background_267k.jpg

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpo…

Published:

26 May 2026 at 22:00:00

Alert date:

27 May 2026 at 23:01:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

The Goobi viewer web application contains a critical vulnerability in versions 4.8.0 to before 26.04.1. The REST endpoint POST /api/v1/index/stream accepts arbitrary Solr streaming expressions from unauthenticated clients and forwards them to the backend Solr server without restriction. This allows attackers to read the complete Solr index and potentially modify or delete indexed records in default Solr deployments. The vulnerability enables unauthorized access to digitized material and database manipulation through injection attacks. The issue has been fixed in version 26.04.1.

Technical details

Mitigation steps:

Affected products:

Goobi viewer

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page