Junglewise Threat Intelligence

CVE-2026-31380: Apache OFBiz Expression Language injection

CVE-2026-31380 · Severity: info · Published 2026-05-19

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz, an open-source enterprise resource planning (ERP) system used for managing business processes, is vulnerable to a security flaw that could allow an attacker to execute unauthorized commands. By injecting malicious code into the system's expression language, an attacker could potentially gain control over the server, access sensitive business data, or disrupt operations. Organizations using this software should upgrade to version 24.09.06 immediately to protect their environment.

Technical details

Apache OFBiz is affected by an Expression Language (EL) Injection vulnerability (CWE-917) due to improper neutralization of special elements used in expression language statements. This vulnerability allows a remote attacker to inject and execute malicious EL expressions, potentially leading to remote code execution (RCE) on the underlying server. The flaw exists in versions prior to 24.09.06. While specific preconditions like authentication requirements are not detailed in the advisory, EL injection typically occurs via unvalidated user input being passed to an expression evaluator. Users are advised to upgrade to version 24.09.06 to mitigate this risk.

Affected products

  • Apache OFBiz versions before 24.09.06

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory

References