Code Injection in Apache OFBiz - CVE-2026-50223
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper control of generation of code in the DataResource FreeMarker template handling functionality when processing attacker-controlled template content. A remote user can inject crafted template expressions to execute arbitrary code.
Exploitation requires Content/DataResource editing privileges.