Apache OFBiz RCE Flaw Abuses Password-Change Restrictions for Authentication Bypass
ID: d84eb4b5-0f3b-57c8-a8b5-5135da71b2d4
STIX ID: report--d84eb4b5-0f3b-57c8-a8b5-5135da71b2d4
Feed Name: GBHackers
Apache OFBiz contains a critical authentication-bypass and remote code execution vulnerability (CVE-2026-45434) affecting all versions prior to 24.09.06: due to improper handling of requirePasswordChange in LoginWorker, a client-controllable flag, and an unsandboxed ProgramExport Groovy evaluator, an attacker can craft a single POST (to /webtools/control/ProgramExport with requirePasswordChange=Y and groovyProgram) to obtain full JVM/OS command execution (tested to root). Apache patched this in 24.09.06 (removing the client parameter, adding permission checks, and introducing a Groovy sandbox); the report includes Suricata/YARA detections and recommended mitigations such as immediate upgrade, removing demo accounts, and restricting access to ProgramExport.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
