Improper Access Control in Apache OFBiz Affects Multi-Tenant Deployments
CVE-2026-31388
5.3MEDIUM
What is CVE-2026-31388?
An improper access control vulnerability exists in Apache OFBiz when deployed in multi-tenant environments. This issue can potentially allow unauthorized access to sensitive information or functionality. Users are urged to upgrade to version 24.09.06 or later to address this vulnerability effectively.
Affected Version(s)
Apache OFBiz 0 < 24.09.06