CVE-2026-47342
published 2026-06-10CVE-2026-47342: A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.41%
33.0th percentile
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges
This issue affects Apache OFBiz: before 24.09.07.
Users are recommended to upgrade to version 24.09.07, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ofbiz | < 24.09.07 | 24.09.07 |
| apache_software_foundation | apache_ofbiz | < 24.09.07 | 24.09.07 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07.
ghsa_unreviewed·2026-06-11
CVE-2026-47342 CWE-285 A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07.
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges
This issue affects Apache OFBiz: before 24.09.07.
Users are recommended to upgrade to version 24.09.07, which fixes the issue.
VulDB
Apache OFBiz up to 24.09.06 updateOrRemove authorization
vuldb·2026-06-10
CVE-2026-47342 [CRITICAL] Apache OFBiz up to 24.09.06 updateOrRemove authorization
A vulnerability described as critical has been identified in Apache OFBiz. The impacted element is the function updateOrRemove. Such manipulation leads to authorization bypass.
This vulnerability is documented as CVE-2026-47342. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-10
Published