Improper Neutralization of Special Elements used in an Expression Language Statement in Apache OFBiz - CVE-2026-31380

 

Improper Neutralization of Special Elements used in an Expression Language Statement in Apache OFBiz - CVE-2026-31380

Published: August 25, 2026


Vulnerability identifier: #VU145272
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31380
CWE-ID: CWE-917
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in an expression language statement in the FreeMarker template processing functionality when handling duplicate parameters that bypass sanitization. A remote attacker can send a specially crafted request to execute arbitrary code.


Affected software

Apache OFBiz

How to mitigate CVE-2026-31380

Install security update from vendor's website.

Apache OFBiz - update to 24.09.06

External References

Related Security Bulletins