Critical Vulnerabilities Discovered in Apache OFBiz Affecting All Versions Pre-24.09.06

Critical Vulnerabilities Discovered in Apache OFBiz Affecting All Versions Pre-24.09.06

First seen 21 May 2026, 15:39 UTC Heise.DeGbhackersaretiq.ai 79% similarity 72.0

Article Content

Browse articles
ThreatCluster

Apache OFBiz has critical vulnerabilities that allow attackers to exploit hardcoded keys and bypass authentication. The vulnerabilities, CVE-2026-31986 and CVE-2026-45434, were published on 2026-05-19 and affect all versions prior to 24.09.06. Attackers can gain unauthorized access and execute remote code through a single HTTP request. The vulnerabilities are particularly dangerous due to the potential for remote code execution. Administrators are urged to upgrade to version 24.09.06 to mitigate risks. As of now, there are no confirmed attacks exploiting these vulnerabilities. Apache OFBiz is widely used for managing business processes, making the impact significant for organizations relying on this software.

Key Points: • Two critical vulnerabilities in Apache OFBiz allow remote code execution and authentication bypass. • CVE-2026-31986 involves a hardcoded key, while CVE-2026-45434 allows remote code execution. • Administrators must upgrade to version 24.09.06 immediately to protect their systems.

ThreatCluster AI

Timeline

2026-05-19
CVE-2026-31986 published
A critical vulnerability in Apache OFBiz allows unauthorized access due to a hardcoded key.
Heise.De
2026-05-19
CVE-2026-45434 published
A high-severity vulnerability enables remote code execution through malicious HTTP requests.
Heise.De
2026-05-20
Security update released
Developers released version 24.09.06 to address 17 vulnerabilities, including critical ones.
Heise.De
2026-05-21
Exploitation risk remains
As of today, there are no confirmed attacks exploiting the vulnerabilities, but risks persist.
Gbhackers

Community

Browse all →