PT-2026-41860 · Apache · Apache Ofbiz

·

CVE-2026-46586

·

Published

2026-05-19

·

Updated

2026-05-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 24.09.06
Description Improper Control of Generation of Code (Code Injection) and Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection) in the 'traverseContent' service allow authenticated Groovy code execution.
Recommendations Upgrade to version 24.09.06.

Exploit

Fix

Code Injection

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46586

Affected Products

Apache Ofbiz