PT-2026-41850 · Apache · Apache Ofbiz

·

CVE-2026-31387

·

Published

2026-05-19

·

Updated

2026-05-19

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 24.09.06
Description Improper Authentication issue in Apache OFBiz where cookie manipulation allows authenticated JWT (JSON Web Token) forgery and account impersonation.
Recommendations Upgrade to version 24.09.06.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31387

Affected Products

Apache Ofbiz