Improper access control in Apache OFBiz - CVE-2026-31388
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in program export feature when exporting program data in multi-tenant deployments. A remote user can access data belonging to another tenant to disclose sensitive information.
Only multi-tenant deployments are vulnerable.