Server-Side Request Forgery Vulnerability in Apache OFBiz
CVE-2026-31910

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
19 May 2026

What is CVE-2026-31910?

A Server-Side Request Forgery (SSRF) vulnerability exists in Apache OFBiz, affecting versions prior to 24.09.06. This vulnerability can allow an attacker to send crafted requests from the server, potentially leading to unauthorized access to internal services and sensitive data. Users are strongly advised to upgrade to version 24.09.06 to mitigate this risk and ensure the security of their applications.

Affected Version(s)

Apache OFBiz 0 < 24.09.06

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Voyag3r-Security
.