Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lwd3C

#29408of 53,630
8.8Total CVSS
Vulnerabilities · 1
PT-2026-41860
8.8
2026-05-19
Apache · Apache Ofbiz · CVE-2026-46586
**Name of the Vulnerable Software and Affected Versions** Apache OFBiz versions prior to 24.09.06 **Description** Improper Control of Generation of Code (Code Injection) and Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection) in the 'traverseContent' service allow authenticated Groovy code execution. **Recommendations** Upgrade to version 24.09.06.