Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution
CVE-2026-50223

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 June 2026

What is CVE-2026-50223?

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution.

This issue affects Apache OFBiz: before 24.09.07.

Users are recommended to upgrade to version 24.09.07, which fixes the issue.

Affected Version(s)

Apache OFBiz 0 < 24.09.07

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yi
Jongyeon Lee
.