Junglewise Threat Intelligence

CVE-2026-31909: Apache OFBiz sensitive information disclosure

CVE-2026-31909 · Severity: info · Published 2026-05-19

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz, an open-source enterprise resource planning (ERP) system, contains a vulnerability that could allow unauthorized individuals to access sensitive information. This could lead to the exposure of internal system details or business data, potentially compromising the privacy and security of the organization's operations. Users are advised to upgrade to the latest version to mitigate this risk.

Technical details

A vulnerability classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) exists in Apache OFBiz versions prior to 24.09.06. The flaw allows an unauthenticated or unauthorized attacker to access information that should be protected, though the specific nature of the data (e.g., configuration files, stack traces, or user data) is not detailed in the advisory. The issue is resolved in version 24.09.06. Security engineers should prioritize upgrading to the patched version to prevent information disclosure that could be used to facilitate further attacks.

Affected products

  • Apache OFBiz before 24.09.06

Timeline

  • 2026-05-19: disclosed: Initial disclosure by Apache Software Foundation
  • 2026-05-19: advisory: NVD publication date

References