Junglewise Threat Intelligence

CVE-2026-45187: Apache OFBiz improper authorization in Webtools

CVE-2026-45187 · Severity: info · Published 2026-05-19

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz is an open-source enterprise resource planning (ERP) system used by businesses to manage various operations. A security flaw in its Webtools component could allow unauthorized users to access administrative functions or data they should not be able to see. This could lead to unauthorized changes to business data or exposure of sensitive internal information.

Technical details

An improper authorization vulnerability (CWE-285) exists in the Webtools component of Apache OFBiz. The flaw resides in the access control mechanisms, potentially allowing a remote attacker to bypass intended restrictions and perform actions within the Webtools interface. While specific exploitation details are not fully disclosed, such vulnerabilities typically involve insufficient validation of user permissions when accessing sensitive endpoints. The issue is resolved in version 24.09.06.

Affected products

  • Apache OFBiz before 24.09.06

Timeline

  • 2026-05-19: advisory: Vulnerability disclosed by Apache Software Foundation
  • 2026-05-19: patched: Fix released in version 24.09.06

References