Issue
Vulnerability scanners flag Apache Log4j Core CVE-2026-34480 in Solr environments. The scanner output identifies that Apache Log4j Core versions up to and including 2.25.3 fail to sanitize characters forbidden by the XML 1.0 specification, producing invalid XML output whenever a log message contains such characters.
Diagnosis
Solr ships with a version of Log4j that falls within the vulnerable range. However, the vulnerability only triggers if XmlLayout is explicitly configured as the Log4j appender layout. Solr uses PatternLayout by default in its logging configuration file. Unless the logging configuration has been manually modified to use XmlLayout, this vulnerability has no impact on the Solr instance.
Even if XmlLayout were in use, the worst outcome is malformed or dropped log records. This is a log-output quality issue rather than a critical security risk like remote code execution or data exfiltration.
Environment
Solr 8.x
Cause
The presence of older log4j-core library files triggers vulnerability scanners based on version detection, even if the vulnerable configuration path is not actively used in the default Solr setup.
Resolution
To remediate the scanner finding, verify that the environment is not exploitable or manually update the Log4j libraries.
Verify non-exploitability
Inspect the Solr logging configuration to confirm that XmlLayout is not in use. Search for the string XmlLayout within all log4j2.xml files located in the Solr installation directory. If no results are returned, the vulnerable code path is not active and the vulnerability is not exploitable.
Manually update Log4j libraries
If a clean vulnerability scan is required for compliance, manually update the Log4j JAR files to version 2.25.4. Apply these changes in a lower environment first to ensure you can revert immediately if a classpath mismatch occurs.
Download the updated JAR files from the official Apache Log4j download page. Ensure you obtain log4j-core, log4j-api, and log4j-slf4j-impl. (include log4j-1.2-api and log4j-web if needed)
Stop the Solr service.
Create a complete backup copy of the current Solr directory structure.
Locate the existing Log4j JAR files in the Solr installation directory. Review the standard paths below:
server/lib/ext/
contrib/prometheus-exporter/lib/
server/solr-webapp/WEB-INF/lib/Remove the old Log4j JAR files from the identified directories.
Place the newly downloaded version 2.25.4 JAR files into the exact same directories.
Restart the Solr service.
Verify the loaded versions by navigating to the Solr Admin UI, selecting Dashboard, opening Java Properties, and searching for log4j.