PT-2026-41845 · Apache · Apache Ofbiz

Published

2026-05-19

·

Updated

2026-05-19

·

CVE-2026-29220

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 24.09.06
Description An improper limitation of a pathname to a restricted directory, also known as path traversal, exists in the Content Component. This allows for low-privilege local file inclusion (LFI), a condition where an application includes files from the local file system that it should not have access to.
Recommendations Upgrade to version 24.09.06.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-29220

Affected Products

Apache Ofbiz