
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45434 is a critical Improper Authentication vulnerability in Apache OFBiz, arising from a flaw in the password-change logic that enables unauthenticated remote code execution. It affects all Apache OFBiz versions before 24.09.06 and was publicly disclosed on May 19, 2026, via the Apache mailing list and oss-security. The vulnerability was reported by Mike Cole and assigned a CVSS v3.1 base score of 9.8 (Critical) per NVD, though the GitHub Advisory Database notes a score of 8.8 (High) with low privileges required (GitHub Advisory, oss-security).
The vulnerability is classified as CWE-287 (Improper Authentication) and stems from a logic flaw in Apache OFBiz's password-change functionality that can be abused to bypass authentication controls (GitHub Advisory, oss-security). An attacker can exploit this flaw over the network with low attack complexity and no user interaction required, leveraging the password-change endpoint to gain unauthorized access and subsequently achieve remote code execution. No public proof-of-concept exploit code has been identified at this time (Feedly). The attack patterns associated with this vulnerability include authentication bypass (CAPEC-115), web shell upload (CAPEC-650), and session hijacking (CAPEC-593).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the affected Apache OFBiz system, resulting in complete compromise of confidentiality, integrity, and availability. An attacker could gain full control of the ERP platform, access sensitive business data (financial records, customer information, supply chain data), deploy web shells for persistent access, and potentially pivot to other internal systems. The broad deployment of Apache OFBiz in enterprise environments amplifies the potential business impact (GitHub Advisory, oss-security).
As of the time of disclosure, there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.287% (0.096% per GitHub Advisory), placing it in the 26th percentile for exploitation likelihood within 30 days. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog based on available information. No specific threat actor attribution has been reported at this time.
/webtools/control/main?USERNAME=&PASSWORD=&requirePasswordChange=Y or similar) from unauthenticated or unknown source IPs; outbound connections from the OFBiz server to external IPs following such requests..jsp, .groovy files) in the OFBiz deployment directory; newly created or modified files in the OFBiz hot-deploy or runtime directories.bash, sh, curl, wget, python); unexpected network connections initiated by the Java process.The primary remediation is to upgrade Apache OFBiz to version 24.09.06 or later, which contains the fix for this vulnerability (oss-security, GitHub Advisory). As interim measures, organizations should restrict network access to OFBiz instances using firewalls or WAF rules, limiting exposure to trusted IP ranges only. Additionally, administrators should monitor and audit password-change activity and authentication logs for suspicious behavior, and consider placing OFBiz behind a reverse proxy with additional authentication controls until patching is complete (Feedly).
The vulnerability received coverage from multiple security news outlets including GBHackers, SecurityOnline, CyberPress, and The Hacker News (in their weekly recap), highlighting the critical nature of the authentication bypass in a widely used ERP platform (GBHackers, SecurityOnline). Check Point Research also published a defense advisory for the vulnerability. Social media discussion was noted on Bluesky and Mastodon/infosec.exchange shortly after disclosure. The Arabian Post framed the issue as raising broader ERP security alarms, reflecting concern about the attack surface of enterprise OFBiz deployments (The Arabian Post).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."