logo

Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws

ID: 637f085c-cb6c-58e0-8ce6-3fce259af89b

STIX ID: report--637f085c-cb6c-58e0-8ce6-3fce259af89b

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

Apache OFBiz released a critical security update (24.09.06) addressing multiple high-severity vulnerabilities—including an authentication bypass (CVE-2026-45434) enabling full RCE via the password-reset logic, input-validation issues allowing JSON attribute/allowlist bypass and RCE (CVE-2026-31378), cookie manipulation leading to JWT forgery and account takeover (CVE-2026-31387), and a template-engine SSTI (CVE-2026-29207). Administrators are urged to upgrade immediately; the release also removes FTL templates and reduces default ecommerce privileges to mitigate attack surface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.