Junglewise Threat Intelligence

CVE-2026-31906: Apache OFBiz cross-site scripting

CVE-2026-31906 · Severity: info · Published 2026-05-19

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz, an open-source enterprise resource planning (ERP) system, is vulnerable to a cross-site scripting (XSS) flaw. This vulnerability could allow an attacker to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized access to user sessions or sensitive business data. Organizations should upgrade to version 24.09.06 to protect their operations and data integrity.

Technical details

A cross-site scripting (XSS) vulnerability exists in Apache OFBiz due to improper neutralization of user-supplied input during web page generation (CWE-79). An attacker can exploit this by injecting malicious scripts into the application, which are then executed in the context of a victim's browser. This typically requires the victim to visit a specially crafted link or view a page containing the malicious payload. Successful exploitation can lead to session hijacking, cookie theft, or unauthorized actions performed on behalf of the user. The issue is resolved in Apache OFBiz version 24.09.06.

Affected products

  • Apache OFBiz before 24.09.06

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory

References