Junglewise Threat Intelligence

CVE-2026-29226: Apache OFBiz SSRF in Content component

CVE-2026-29226 · Severity: info · Published 2026-05-19

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz, an open-source enterprise resource planning (ERP) system, contains a security flaw in its Content component. An attacker can exploit this to make the server perform unauthorized network requests to internal or external systems. This could lead to the exposure of sensitive internal data or allow the attacker to bypass network security controls to reach other systems within the corporate environment.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Content component of Apache OFBiz. The flaw is categorized as CWE-918 and stems from insufficient validation of user-supplied URLs or parameters during Content component operations. A remote attacker can leverage this to force the server to initiate requests to arbitrary destinations, potentially accessing internal services that are not exposed to the public internet or scanning the internal network. The issue is resolved in version 24.09.06.

Affected products

  • Apache OFBiz before 24.09.06

Timeline

  • 2026-05-19: advisory: Initial disclosure by Apache Software Foundation
  • 2026-05-19: patched: Fix released in version 24.09.06

References