Input validation error in Apache OFBiz - CVE-2026-31378
Published: August 25, 2026
Vulnerability identifier: #VU145273
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31378
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in Apache OFBiz when processing crafted JSON input that can override attributes and bypass URL allowlist restrictions. A remote attacker can send specially crafted input to execute arbitrary code.
Affected software
Apache OFBiz
How to mitigate CVE-2026-31378
Install security update from vendor's website.
Apache OFBiz - update to 24.09.06