PT-2026-41846 · Apache · Apache Ofbiz

Duanjinshi@163.Com

+1

·

Published

2026-05-19

·

Updated

2026-05-19

·

CVE-2026-29226

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 24.09.06
Description Server-Side Request Forgery (SSRF) in the Content component operations. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
Recommendations Upgrade to version 24.09.06.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-29226

Affected Products

Apache Ofbiz