
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45187 is an Improper Authorization vulnerability in Apache OFBiz Webtools that allows low-privileged or unauthenticated users to submit system-level scheduled jobs without proper authorization checks. It affects all versions of Apache OFBiz before 24.09.06 and was publicly disclosed on May 19, 2026. The vulnerability was reported by security researcher Qiulin Deng and assigned a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Openwall OSS-Sec).
The vulnerability is classified as CWE-285 (Improper Authorization) and resides specifically in the Apache OFBiz Webtools component's scheduled job creation functionality. Due to insufficient authorization enforcement, low-privileged users can bypass access controls and submit system-level jobs that should be restricted to administrators. The attack vector is network-based, requires no user interaction, and has low attack complexity, meaning it can be exploited remotely without authentication barriers beyond having network access to the OFBiz Webtools interface (Openwall OSS-Sec, GitHub Advisory).
Successful exploitation allows an attacker to bypass authorization checks in OFBiz Webtools, gaining the ability to read sensitive information (low confidentiality impact) and modify data by submitting unauthorized system-level scheduled jobs (low integrity impact). Availability is not directly impacted. The ability to create and execute system jobs could potentially be leveraged for further privilege escalation or persistent access within the OFBiz environment (GitHub Advisory, Feedly).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.244% (48th percentile), indicating a relatively low near-term exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by Qiulin Deng, with no known threat actor attribution at this time (Openwall OSS-Sec).
/webtools/)./webtools/ from external IP addresses.Apache has released version 24.09.06 of OFBiz, which fixes this vulnerability, and users are strongly recommended to upgrade immediately (Openwall OSS-Sec, GitHub Advisory). As a temporary workaround until patching is completed, administrators should restrict network access to the OFBiz Webtools administrative interface to trusted internal networks only, using firewall rules or network segmentation. Reviewing and auditing existing scheduled jobs for unauthorized entries is also recommended as a post-incident check.
The vulnerability was disclosed via the Apache security mailing list and the oss-security mailing list on May 19, 2026, by Jacopo Cappellato on behalf of the Apache OFBiz project (Openwall OSS-Sec). A Bluesky post from the infosec community noted the disclosure shortly after publication. Overall community reaction has been measured given the moderate severity rating and absence of public exploits.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."