Executive brief
A code injection vulnerability has been identified in the email services of Apache OFBiz, an open-source enterprise resource planning (ERP) system. This flaw could allow an attacker to execute unauthorized code within the application, potentially leading to full system compromise or unauthorized access to sensitive business data. Organizations using OFBiz should upgrade to version 24.09.06 to mitigate this risk.
Technical details
A code injection vulnerability (CWE-94) exists in the email services component of Apache OFBiz. The flaw stems from improper control of code generation, which can be exploited by an attacker to inject and execute malicious code on the server. While specific exploitation details are not fully disclosed in the advisory, such vulnerabilities typically involve the manipulation of input parameters processed by the email subsystem. The issue is resolved in version 24.09.06.
Affected products
- Apache OFBiz before 24.09.06
Timeline
- 2026-05-19: disclosed
- 2026-05-19: advisory