Expression Language Injection Vulnerability in Apache OFBiz by Apache
CVE-2026-31380

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
19 May 2026

What is CVE-2026-31380?

An Expression Language Injection vulnerability has been identified in Apache OFBiz, allowing attackers to manipulate expressions used in the application. This flaw can be exploited by an adversary to execute unauthorized commands through specially crafted input, potentially compromising the security of web applications relying on the affected version. Users are advised to upgrade to version 24.09.06 or later to remediate this vulnerability and enhance their application's resilience against exploitation.

Affected Version(s)

Apache OFBiz 0 < 24.09.06

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sho Odagiri of GMO Cybersecurity by Ierae, Inc.
.