CVE-2026-29226
published 2026-05-19CVE-2026-29226: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are…
PriorityP344high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.47%
37.9th percentile
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 24.09.06 | 24.09.06 |
| apache_software_foundation | apache_ofbiz | < 24.09.06 | 24.09.06 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache OFBiz up to 24.09.05 Content Component Operation server-side request forgery
vuldb·2026-05-23·CVSS 7.3
CVE-2026-29226 [HIGH] Apache OFBiz up to 24.09.05 Content Component Operation server-side request forgery
A vulnerability was found in Apache OFBiz up to 24.09.05. It has been rated as critical. This vulnerability affects unknown code of the component Content Component Operation Handler. This manipulation causes server-side request forgery.
The identification of this vulnerability is CVE-2026-29226. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-ppv4-wf78-868j: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations
ghsa_unreviewed·2026-05-19
CVE-2026-29226 [HIGH] CWE-918 GHSA-ppv4-wf78-868j: Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-19
Published