CVE-2026-31387
published 2026-05-19CVE-2026-31387: Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.52%
40.2th percentile
Improper Authentication vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 24.09.06 | 24.09.06 |
| apache_software_foundation | apache_ofbiz | < 24.09.06 | 24.09.06 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache OFBiz up to 24.09.05 improper authentication
vuldb·2026-05-23·CVSS 5.3
CVE-2026-31387 [MEDIUM] Apache OFBiz up to 24.09.05 improper authentication
A vulnerability marked as critical has been reported in Apache OFBiz up to 24.09.05. The impacted element is an unknown function. The manipulation leads to improper authentication.
This vulnerability is listed as CVE-2026-31387. The attack must be carried out from within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
GHSA-3wxm-wq6x-mq3g: Improper Authentication vulnerability in Apache OFBiz
ghsa_unreviewed·2026-05-19
CVE-2026-31387 [MEDIUM] CWE-287 GHSA-3wxm-wq6x-mq3g: Improper Authentication vulnerability in Apache OFBiz
Improper Authentication vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-19
Published