Input validation error in Apache OFBiz - CVE-2026-31378

 

Input validation error in Apache OFBiz - CVE-2026-31378

Published: August 25, 2026


Vulnerability identifier: #VU145273
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-31378
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in Apache OFBiz when processing crafted JSON input that can override attributes and bypass URL allowlist restrictions. A remote attacker can send specially crafted input to execute arbitrary code.


Affected software

Apache OFBiz

How to mitigate CVE-2026-31378

Install security update from vendor's website.

Apache OFBiz - update to 24.09.06

External References

Related Security Bulletins