Junglewise Threat Intelligence

CVE-2026-47342: Apache OFBiz privilege escalation in updateOrRemove functionality

CVE-2026-47342 · Severity: info · CVSS 6.5 · Published 2026-06-10

Technologies: Apache OFBiz. Vendors: Apache.

Executive brief

Apache OFBiz, an open-source enterprise resource planning (ERP) system, contains a security flaw that allows a user with limited access to gain higher-level administrative permissions. By exploiting this vulnerability, an internal user could potentially modify or delete sensitive business data they are not authorized to manage. This could lead to unauthorized changes in financial records, inventory, or customer information.

Technical details

A privilege escalation vulnerability exists in Apache OFBiz due to improper authorization (CWE-285) within the 'updateOrRemove' functionality. An authenticated attacker with low-level privileges can bypass intended access controls to perform actions or access data reserved for higher-privileged roles. The vulnerability is reachable over the network and requires valid user credentials but no special administrative rights. Exploitation allows for unauthorized modification or deletion of records. The issue is resolved in version 24.09.07.

Affected products

  • Apache OFBiz before 24.09.07

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory
  • 2026-06-10: patched: Fixed in version 24.09.07

References