CVE-2026-31909
7.5Apache · OFBiz
An information disclosure vulnerability in Apache OFBiz allows unauthenticated attackers to access sensitive data due to inadequate access controls.
Executive summary
An unauthenticated information exposure vulnerability in Apache OFBiz could allow an attacker to gain access to sensitive system or business data.
Vulnerability
This is an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability. Based on the CVSS vector AV:N/AC:L/PR:N, the vulnerability is reachable by an unauthenticated attacker via the network.
Business impact
Successful exploitation could result in the unauthorized disclosure of sensitive business information, potentially including customer data, system configuration details, or credentials. A CVSS score of 7.5 reflects the high impact on confidentiality, which could lead to regulatory compliance failures and reputational harm.
Remediation
Immediate Action: Upgrade to Apache OFBiz version 24.09.06 or later to apply the necessary security fixes.
Proactive Monitoring: Review application access logs for unusual patterns or bulk data retrieval requests that may indicate an attempt to exploit this information disclosure.
Compensating Controls: Ensure the OFBiz instance is not exposed to the public internet unless strictly necessary, and enforce strict access controls at the network level.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for unauthorized data access, immediate remediation is required. Organizations should apply the vendor-provided update to version 24.09.06 as soon as possible to ensure the confidentiality of their data.