Executive brief
Apache OFBiz, an open-source enterprise resource planning (ERP) suite, contains a security flaw that allows certain authorized users to execute unauthorized commands on the server. An attacker with basic permissions to edit content or data resources can exploit this to take full control of the application and its underlying data. This could lead to a total compromise of business operations and sensitive corporate information.
Technical details
A Server-Side Template Injection (SSTI) vulnerability exists in Apache OFBiz due to improper control of code generation within the DataResource editing component. Specifically, the application fails to sufficiently sanitize user-provided input used in FreeMarker templates. An authenticated attacker with 'Content/DataResource' editing privileges can inject malicious FreeMarker directives to execute arbitrary Java code on the server. This vulnerability is exploited over the network and results in full Remote Code Execution (RCE) under the context of the OFBiz service. The issue is resolved in version 24.09.07.
Affected products
- Apache OFBiz before 24.09.07
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory
- 2026-06-10: patched: Fixed in version 24.09.07