CVE-2026-31909

7.5

Apache · OFBiz

An information disclosure vulnerability in Apache OFBiz allows unauthenticated attackers to access sensitive data due to inadequate access controls.

Executive summary

An unauthenticated information exposure vulnerability in Apache OFBiz could allow an attacker to gain access to sensitive system or business data.

Vulnerability

This is an Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability. Based on the CVSS vector AV:N/AC:L/PR:N, the vulnerability is reachable by an unauthenticated attacker via the network.

Business impact

Successful exploitation could result in the unauthorized disclosure of sensitive business information, potentially including customer data, system configuration details, or credentials. A CVSS score of 7.5 reflects the high impact on confidentiality, which could lead to regulatory compliance failures and reputational harm.

Remediation

Immediate Action: Upgrade to Apache OFBiz version 24.09.06 or later to apply the necessary security fixes.

Proactive Monitoring: Review application access logs for unusual patterns or bulk data retrieval requests that may indicate an attempt to exploit this information disclosure.

Compensating Controls: Ensure the OFBiz instance is not exposed to the public internet unless strictly necessary, and enforce strict access controls at the network level.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for unauthorized data access, immediate remediation is required. Organizations should apply the vendor-provided update to version 24.09.06 as soon as possible to ensure the confidentiality of their data.

More Apache CVEs