logo

Apache OFBiz RCE Flaw Abuses Password-Change Restrictions for Authentication Bypass

ID: d84eb4b5-0f3b-57c8-a8b5-5135da71b2d4

STIX ID: report--d84eb4b5-0f3b-57c8-a8b5-5135da71b2d4

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Divya

...
...

Apache OFBiz contains a critical authentication-bypass and remote code execution vulnerability (CVE-2026-45434) affecting all versions prior to 24.09.06: due to improper handling of requirePasswordChange in LoginWorker, a client-controllable flag, and an unsandboxed ProgramExport Groovy evaluator, an attacker can craft a single POST (to /webtools/control/ProgramExport with requirePasswordChange=Y and groovyProgram) to obtain full JVM/OS command execution (tested to root). Apache patched this in 24.09.06 (removing the client parameter, adding permission checks, and introducing a Groovy sandbox); the report includes Suricata/YARA detections and recommended mitigations such as immediate upgrade, removing demo accounts, and restricting access to ProgramExport.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.