top of page
perceptive_background_267k.jpg

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpo…

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 23:01:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage

The Goobi viewer web application contains a critical vulnerability in versions 4.8.0 to before 26.04.1. The REST endpoint POST /api/v1/index/stream accepts arbitrary Solr streaming expressions from unauthenticated clients and forwards them to the backend Solr server without restriction. This allows attackers to read the complete Solr index and potentially modify or delete indexed records in default Solr deployments. The vulnerability enables unauthorized access to digitized material and database manipulation through injection attacks. The issue has been fixed in version 26.04.1.

Technical details

Mitigation steps:

Affected products:

Goobi viewer

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page