Junglewise Threat Intelligence

CVE-2026-31910: Apache OFBiz Server-Side Request Forgery

CVE-2026-31910 · Severity: info · Published 2026-05-19

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz, an open-source enterprise resource planning (ERP) system, is vulnerable to a security flaw that could allow an attacker to trick the server into making unauthorized requests. This could lead to the exposure of internal network information or sensitive data that is not normally accessible from the outside. Organizations using OFBiz should update to version 24.09.06 to protect their internal infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Apache OFBiz versions prior to 24.09.06. The flaw, classified as CWE-918, occurs when the application processes user-supplied URLs without sufficient validation, allowing the server to be used as a proxy to send requests to internal or external resources. An attacker can leverage this to scan internal networks, bypass firewalls, or access metadata services. The issue is resolved in version 24.09.06.

Affected products

  • Apache OFBiz before 24.09.06

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: advisory

References