Code Injection Vulnerability in Apache OFBiz Email Services
CVE-2026-35086
6.5MEDIUM
What is CVE-2026-35086?
An improper control of code generation vulnerability exists in the email services of Apache OFBiz. This flaw could potentially allow an attacker to execute arbitrary code within the application's context. It is crucial for users of affected versions to upgrade to version 24.09.06 or later to mitigate this risk and ensure the security of their systems.
Affected Version(s)
Apache OFBiz 0 < 24.09.06