Executive brief
Apache OFBiz, an open-source enterprise resource planning (ERP) system used for managing business processes, is vulnerable to a security flaw in its template engine. An attacker could exploit this to execute unauthorized commands or access sensitive data by injecting malicious code into templates. This could lead to a full system compromise or unauthorized access to corporate data.
Technical details
Apache OFBiz is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336), commonly known as Server-Side Template Injection (SSTI). The vulnerability exists in the handling of FreeMarker Template Language (FTL) data resources. An attacker with sufficient permissions—or by leveraging overly broad default permissions in the 'Ecommerce Customer' security group—could inject malicious FTL syntax to achieve remote code execution. The fix involves disabling support for 'FTL' dataTemplateTypeId records and hardening the default permissions for ecommerce users. Users should upgrade to version 24.09.06 and manually audit security group permissions.
Affected products
- Apache OFBiz before 24.09.06
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory
- 2026-05-19: patched: Fixed in version 24.09.06