CVE-2026-45187
Apache OFBiz vulnerability analysis and mitigation

Overview

CVE-2026-45187 is an Improper Authorization vulnerability in Apache OFBiz Webtools that allows low-privileged or unauthenticated users to submit system-level scheduled jobs without proper authorization checks. It affects all versions of Apache OFBiz before 24.09.06 and was publicly disclosed on May 19, 2026. The vulnerability was reported by security researcher Qiulin Deng and assigned a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Openwall OSS-Sec).

Technical details

The vulnerability is classified as CWE-285 (Improper Authorization) and resides specifically in the Apache OFBiz Webtools component's scheduled job creation functionality. Due to insufficient authorization enforcement, low-privileged users can bypass access controls and submit system-level jobs that should be restricted to administrators. The attack vector is network-based, requires no user interaction, and has low attack complexity, meaning it can be exploited remotely without authentication barriers beyond having network access to the OFBiz Webtools interface (Openwall OSS-Sec, GitHub Advisory).

Impact

Successful exploitation allows an attacker to bypass authorization checks in OFBiz Webtools, gaining the ability to read sensitive information (low confidentiality impact) and modify data by submitting unauthorized system-level scheduled jobs (low integrity impact). Availability is not directly impacted. The ability to create and execute system jobs could potentially be leveraged for further privilege escalation or persistent access within the OFBiz environment (GitHub Advisory, Feedly).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.244% (48th percentile), indicating a relatively low near-term exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by Qiulin Deng, with no known threat actor attribution at this time (Openwall OSS-Sec).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Apache OFBiz instances running versions prior to 24.09.06 using tools like Shodan or Censys, targeting the Webtools interface (typically accessible at /webtools/).
  2. Access Webtools endpoint: Navigate to the OFBiz Webtools scheduled job creation endpoint without administrator credentials, leveraging the improper authorization flaw.
  3. Submit unauthorized system job: Craft and submit a request to create a system-level scheduled job that would normally require elevated privileges, bypassing the authorization check.
  4. Achieve objective: The submitted job executes with system-level permissions, potentially enabling data access, data modification, or further actions within the OFBiz environment (Openwall OSS-Sec, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP requests to OFBiz Webtools scheduled job creation endpoints from low-privileged or unauthenticated users; unusual access patterns to /webtools/ from external IP addresses.
  • Logs: OFBiz application logs showing scheduled job creation events initiated by accounts without administrative roles; authorization-related log entries indicating access to restricted Webtools functionality.
  • Application: Unexpected or unauthorized scheduled jobs appearing in the OFBiz job scheduler; system jobs created outside of normal administrative workflows or change management processes.

Mitigation and workarounds

Apache has released version 24.09.06 of OFBiz, which fixes this vulnerability, and users are strongly recommended to upgrade immediately (Openwall OSS-Sec, GitHub Advisory). As a temporary workaround until patching is completed, administrators should restrict network access to the OFBiz Webtools administrative interface to trusted internal networks only, using firewall rules or network segmentation. Reviewing and auditing existing scheduled jobs for unauthorized entries is also recommended as a post-incident check.

Community reactions

The vulnerability was disclosed via the Apache security mailing list and the oss-security mailing list on May 19, 2026, by Jacopo Cappellato on behalf of the Apache OFBiz project (Openwall OSS-Sec). A Bluesky post from the infosec community noted the disclosure shortly after publication. Overall community reaction has been measured given the moderate severity rating and absence of public exploits.

Additional resources


SourceThis report was generated using AI

Related Apache OFBiz vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45434CRITICAL9.8
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesMay 19, 2026
CVE-2026-50223HIGH8.8
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesJun 10, 2026
CVE-2026-47342HIGH8.8
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesJun 10, 2026
CVE-2026-46586HIGH8.8
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesMay 19, 2026
CVE-2026-45187MEDIUM6.5
  • Apache OFBiz logoApache OFBiz
  • cpe:2.3:a:apache:ofbiz
NoYesMay 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management