Junglewise Threat Intelligence

CVE-2026-31388: Apache OFBiz improper access control in multi-tenant deployments

CVE-2026-31388 · Severity: info · Published 2026-05-19

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz, an open-source enterprise resource planning (ERP) suite, contains a security flaw in how it manages access for multi-tenant environments. In a multi-tenant setup where different organizations share the same software instance, this vulnerability could allow unauthorized users to access data or functions belonging to other tenants. This poses a risk to data privacy and operational integrity for businesses relying on shared OFBiz deployments.

Technical details

An improper access control vulnerability (CWE-284) exists in Apache OFBiz versions prior to 24.09.06 when configured for multi-tenancy. The flaw resides in the mechanism that isolates tenant data and administrative functions, potentially allowing a user authenticated to one tenant to bypass restrictions and interact with another tenant's environment. While specific exploitation details are not provided in the advisory, such vulnerabilities typically involve manipulation of tenant identifiers in web requests. The issue is resolved in version 24.09.06.

Affected products

  • Apache OFBiz before 24.09.06

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: patched: Fixed in version 24.09.06

References