PT-2026-41850 · Apache · Apache Ofbiz

Sho Odagiri

·

Published

2026-05-19

·

Updated

2026-05-19

·

CVE-2026-31387

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 24.09.06
Description Improper Authentication issue in Apache OFBiz where cookie manipulation allows authenticated JWT (JSON Web Token) forgery and account impersonation.
Recommendations Upgrade to version 24.09.06.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-31387

Affected Products

Apache Ofbiz