Critical RCE Exploits Exposed: Apache OFBiz Patches Severe Authentication Bypass Flaws
ID: 637f085c-cb6c-58e0-8ce6-3fce259af89b
STIX ID: report--637f085c-cb6c-58e0-8ce6-3fce259af89b
Feed Name: securityonline.info
Apache OFBiz released a critical security update (24.09.06) addressing multiple high-severity vulnerabilities—including an authentication bypass (CVE-2026-45434) enabling full RCE via the password-reset logic, input-validation issues allowing JSON attribute/allowlist bypass and RCE (CVE-2026-31378), cookie manipulation leading to JWT forgery and account takeover (CVE-2026-31387), and a template-engine SSTI (CVE-2026-29207). Administrators are urged to upgrade immediately; the release also removes FTL templates and reduces default ecommerce privileges to mitigate attack surface.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
