CVE-2026-41919
published 2026-05-19CVE-2026-41919: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…
PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.45%
37.0th percentile
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 24.09.06 | 24.09.06 |
| apache_software_foundation | apache_ofbiz | < 24.09.06 | 24.09.06 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache OFBiz up to 24.09.05 ldap injection
vuldb·2026-05-23·CVSS 9.1
CVE-2026-41919 [CRITICAL] Apache OFBiz up to 24.09.05 ldap injection
A vulnerability was found in Apache OFBiz up to 24.09.05 and classified as problematic. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to ldap injection.
This vulnerability is handled as CVE-2026-41919. The attack can only be done within the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-9pfq-c8xc-7q54: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz
ghsa_unreviewed·2026-05-19
CVE-2026-41919 [CRITICAL] CWE-90 GHSA-9pfq-c8xc-7q54: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-19
Published