logo

Critical Apache OFBiz Vulnerability Allows Preauth RCE

ID: 6ff3497d-1b82-520d-9d02-d684f780637a

STIX ID: report--6ff3497d-1b82-520d-9d02-d684f780637a

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-08-05

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

A critical pre-authentication RCE (CVE-2024-38856, CVSS 9.8) was disclosed in Apache OFBiz's override view functionality that can allow attackers to access critical endpoints via crafted requests. SonicWall Capture Labs discovered the flaw and recommends upgrading to OFBiz version 18.12.15 or later; approximately 170 OFBiz customers — including major organizations — may be impacted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.