CVE-2025-54466
Apache OFBiz vulnerability analysis and mitigation

Overview

CVE-2025-54466 is a Code Injection vulnerability (CWE-94) in the Apache OFBiz scrum plugin that can lead to Remote Code Execution (RCE) by unauthenticated attackers. It affects Apache OFBiz versions before 24.09.02 only when the scrum plugin is enabled. The vulnerability was discovered by Teeramet Eakwilai, Thanasin Luangpipat, and Jarukit Auikritskul, disclosed publicly on August 5, 2025 via the oss-security mailing list, and assigned a CVSS v3.1 base score of 9.8 (Critical) (oss-security, Red Hat CVE).

Technical details

The root cause is improper control of code generation (CWE-94) within the Apache OFBiz scrum plugin, where user-supplied input is not adequately sanitized before being used in code execution contexts. An unauthenticated remote attacker can send a crafted network request to the vulnerable scrum plugin endpoint, triggering arbitrary code injection and execution on the server without requiring any credentials or user interaction. The vulnerability is only present when the scrum plugin is actively deployed; installations without the plugin are not affected. The issue is tracked upstream as OFBIZ-13276 (oss-security, Apache Jira).

Impact

Successful exploitation grants an unauthenticated attacker full remote code execution on the affected Apache OFBiz server, resulting in complete compromise of confidentiality, integrity, and availability. An attacker could exfiltrate sensitive business data (ERP records, customer data, financial information), modify or destroy data, install persistent backdoors, and use the compromised server as a pivot point for lateral movement within the internal network (oss-security, Red Hat CVE).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.066%, reflecting a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. No threat actor attribution has been reported. However, the zero-authentication requirement and critical CVSS score make it a high-priority target if a public exploit becomes available.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Apache OFBiz instances using tools like Shodan or Censys, filtering for versions prior to 24.09.02. Confirm the scrum plugin is enabled by probing known scrum plugin endpoints.
  2. Identify vulnerable endpoint: Locate the specific scrum plugin endpoint(s) that process user-controlled input without proper sanitization (tracked as OFBIZ-13276).
  3. Craft malicious payload: Construct an HTTP request containing a code injection payload targeting the vulnerable parameter in the scrum plugin, designed to execute arbitrary server-side code.
  4. Send unauthenticated request: Submit the crafted request to the target OFBiz server without any authentication headers or session tokens.
  5. Achieve RCE: The injected code executes in the context of the OFBiz application server process, enabling the attacker to run arbitrary commands, establish a reverse shell, exfiltrate data, or deploy persistent malware (oss-security, Apache Jira).

Indicators of compromise

  • Network: Unexpected or anomalous HTTP requests to Apache OFBiz scrum plugin endpoints from external or unknown IP addresses; outbound connections from the OFBiz server to unknown external hosts (potential reverse shell or C2 traffic).
  • Logs: OFBiz application logs showing unusual or malformed requests to scrum plugin URLs; Java exception stack traces related to code evaluation or class loading errors; access log entries with encoded or obfuscated payloads in request parameters.
  • File System: Newly created or modified files in the OFBiz installation directory, especially web shells, scripts, or unexpected JAR files; new cron jobs or scheduled tasks created by the OFBiz service account.
  • Process: Unusual child processes spawned by the OFBiz Java process (e.g., /bin/bash, cmd.exe, curl, wget, python, powershell); unexpected network listeners opened by the Java process.

Mitigation and workarounds

The primary remediation is to upgrade Apache OFBiz to version 24.09.02 or later, which contains the fix for this vulnerability (oss-security, Apache Security). If an immediate upgrade is not feasible, disable the scrum plugin to eliminate the attack surface. Additionally, implement network segmentation to restrict access to the OFBiz instance to trusted networks only, and monitor for unusual system activity. Review the release notes for version 24.09.02 for full details on the fix (Apache Release Notes).

Community reactions

The vulnerability was disclosed via the oss-security mailing list on August 5, 2025, by Nicolas Malin on behalf of the Apache OFBiz security team (oss-security). Red Hat has acknowledged the CVE and published an advisory (Red Hat CVE). Check Point and Trend Micro have also catalogued the vulnerability in their threat encyclopedias. Community discussion has been limited, with no major public controversy or notable researcher commentary beyond standard vulnerability tracking.

Additional resources


SourceThis report was generated using AI

Related Apache OFBiz vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45434CRITICAL9.8
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesMay 19, 2026
CVE-2026-50223HIGH8.8
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesJun 10, 2026
CVE-2026-47342HIGH8.8
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesJun 10, 2026
CVE-2026-46586HIGH8.8
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesMay 19, 2026
CVE-2026-45187MEDIUM6.5
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesMay 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management