Improper Neutralization in Apache OFBiz Template Engine
CVE-2026-29207

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
19 May 2026

What is CVE-2026-29207?

A vulnerability exists in Apache OFBiz that allows improper neutralization of special elements used in the template engine. This issue affects versions prior to 24.09.06. Users should upgrade to the patched version to mitigate the risk, which introduces significant changes: 'Data Resource' records with dataTemplateTypeId = 'FTL' are deprecated, and the 'Ecommerce Customer' security group is stripped of content management grants. It's crucial for users to ensure these permissions are removed from any production environments to maintain security.

Affected Version(s)

Apache OFBiz 0 < 24.09.06

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lidor B / thisis0xczar of Novee Security
Sho Odagiri of GMO Cybersecurity by Ierae, Inc.
.