Junglewise Threat Intelligence

CVE-2026-45434: Apache OFBiz remote code execution via password-change logic flaw

CVE-2026-45434 · Severity: info · Published 2026-05-19

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz, an open-source enterprise resource planning (ERP) system used for managing business processes, contains a security flaw in its password-change functionality. An attacker can exploit this logic error to bypass authentication and gain unauthorized control over the server. This could lead to the complete takeover of the system, potentially exposing sensitive business data and disrupting operations.

Technical details

A vulnerability exists in Apache OFBiz due to a logic flaw in the password-change mechanism (CWE-287). By exploiting this improper authentication, a remote, unauthenticated attacker can bypass security controls to achieve remote code execution (RCE) on the underlying server. The flaw is present in versions prior to 24.09.06. While specific technical details of the logic bypass are not fully disclosed in the advisory, the impact is categorized as RCE, suggesting a high-impact compromise of the application context. Users are advised to upgrade to version 24.09.06 to mitigate this risk.

Affected products

  • Apache OFBiz before 24.09.06

Timeline

  • 2026-05-19: disclosed: Initial advisory publication
  • 2026-05-19: patched: Fixed in version 24.09.06

References