
[CIVN-2026-0278] Remote Code Execution Vulnerability in Apache OFBiz
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution Vulnerability in Apache OFBiz
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Apache OFBiz versions prior to 24.09.06
Overview
A vulnerability has been reported in Apache OFBiz which may allow a remote attacker to bypass authentication restrictions and execute arbitrary code on the targeted system.
Target Audience:
Individuals and organizations that uses the affected Apache OFBiz platform.
Risk Assessment:
High risk of remote code execution, authentication bypass, and unauthorized access.
Impact Assessment:
Remote code execution, disclosure or manipulation of sensitive information, and complete compromise of the targeted system.
Description
Apache OFBiz is an open-source enterprise resource planning (ERP) and business automation platform.
This vulnerability exists due to improper authentication in the password-change functionality of Apache OFBiz. A remote attacker can exploit this flaw to bypass authentication restrictions and execute arbitrary commands on the underlying server.
Successful exploitation of this vulnerability may allow an attacker to gain unauthorized administrative access and execute arbitrary code on the targeted system.
Solution
Users are advised to apply appropriate updates as mentioned:
https://lists.apache.org/thread/yw4owrzl0yho1yx7oqxvr6xjkmln9tq8
Vendor Information
https://lists.apache.org/thread/yw4owrzl0yho1yx7oqxvr6xjkmln9tq8
References
https://gbhackers.com/apache-ofbiz-rce-flaw-abuses-password-change-restrictions/
CVE Name
CVE-2026-45434
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmogM0wACgkQ3jCgcSdc
ys/v/w/+KB/wrQwjniMIdgzKxgfmpgX1u9n/PAV+7EgcTA9WhNYmAxx4ugTnsXdH
WHOfOvcTFe3qGxGVijLODpZgPkvs0QaBIkO70YhGODhWaR7hAO1bDcPGKzw+VmH6
iQn8F41fDA/ml8xYuyhhIsniS2OhNHCSpii0wZETGvOFFssaKQVD1jUbfbV0AJaV
TOieRkVGUm43f8eUVdmh6tVvl4QCJzzdeOU34LUWF0ufc4Dxf/9VSRwgZu8IyQ82
Yc2KWyOqYswV1M5BVeYrnG+kzupq4t2QXawE+UKmPDffuVnVHfPhzbNwobOcAUrc
r8oGx8sAPmS372rBsU2qG34/FrqM8vnTWBRwQtiq3+VoV/zjQ9XG0KNsdNA32qr9
Ra8G8mw6tAi5G1hx0t7M+/xvEazxZHT9cNLSyUCl+vZpmW+MG0ZkF2sh/HjxeIcn
TWBovnxZ7x6dWJ8g2emY1GeqSrKO2y6H0V6wwYK5Prg3/nF7L3KZvcLyHwZPRdyM
SFKqbvvILq6jRK8vtvGI9NbuLKcMFXP6FHqjxoTIX9woubndkUphVo0Vn63ZAH54
0vG8s9B6X89aqMG7OfWDUBCuHr+Z123lH90/nC6Y9XqkZanGP0kfwDxSMO4zQnMz
c27upDAR92CtNInZI6JQR/t2hhoMLYYsP4X1mk0p0aZKTslpwK8=
=ZT1P
—–END PGP SIGNATURE—–


