PT-2026-41860 · Apache · Apache Ofbiz

Lwd3C

·

Published

2026-05-19

·

Updated

2026-05-21

·

CVE-2026-46586

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache OFBiz versions prior to 24.09.06
Description Improper Control of Generation of Code (Code Injection) and Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection) in the 'traverseContent' service allow authenticated Groovy code execution.
Recommendations Upgrade to version 24.09.06.

Fix

Eval Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-46586

Affected Products

Apache Ofbiz