
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-47342 is a privilege escalation vulnerability in Apache OFBiz, officially titled "Privilege Escalation via updateOrRemove Authorization Bypass." It allows a low-privileged authenticated user to obtain higher privileges, including potential FULLADMIN access, by exploiting improper authorization checks. All Apache OFBiz versions before 24.09.07 are affected. The vulnerability was disclosed on June 10, 2026, by Apache, with credit to researcher Le Huynh Duc (lwd3c). It carries a CVSS v3.1 base score of 8.8 (High) (Apache Advisory, GitHub Advisory).
The root cause is classified as CWE-285 (Improper Authorization) — the application fails to correctly enforce authorization checks when a low-privileged user attempts to access or modify restricted resources. Specifically, the vulnerability resides in the updateOrRemove functionality, where a crafted request to the /ordermgr/control/updateFeatures endpoint with a manipulated UserLoginSecurityGroup payload can bypass access controls. The attack is network-based, requires only low privileges (a valid authenticated session), and demands no user interaction. A public PoC demonstrates full-chain exploitation including privilege escalation to FULLADMIN and subsequent Remote Code Execution (RCE) via Groovy injection (oss-security, PoC GitHub).
Successful exploitation allows a low-privileged authenticated attacker to escalate to administrative (FULLADMIN) privileges within Apache OFBiz, resulting in high impact to confidentiality, integrity, and availability. An attacker with elevated privileges can access sensitive business data, modify configurations, and — as demonstrated in the public PoC — achieve Remote Code Execution via Groovy injection, potentially leading to full system compromise. This could enable lateral movement within the network, data exfiltration, and persistent backdoor installation (GitHub Advisory, PoC GitHub).
A fully functional public proof-of-concept exploit is available on GitHub, consisting of automated bash scripts (create_buyer_user.sh and poc_fullchain.sh) that demonstrate end-to-end exploitation including privilege escalation to FULLADMIN and RCE via Groovy injection against a live Apache OFBiz deployment (PoC GitHub). The vulnerability was discovered and reported by researcher Le Huynh Duc (lwd3c), who also authored the PoC (oss-security). As of the time of reporting, there is no confirmed evidence of in-the-wild exploitation, and the vulnerability has not been added to the CISA KEV catalog. The EPSS score is approximately 0.017–0.343%, indicating a currently low but non-negligible exploitation probability (GitHub Advisory).
create_buyer_user.sh to automate creation of such an account on the target./ordermgr/control/updateFeatures with a manipulated UserLoginSecurityGroup payload that references a higher-privilege security group (e.g., FULLADMIN), exploiting the missing authorization check in the updateOrRemove function.poc_fullchain.sh, resulting in arbitrary command execution as the OFBiz service user) (PoC GitHub, oss-security)./ordermgr/control/updateFeatures from low-privileged user sessions; unexpected outbound connections from the OFBiz server to external IPs following privilege escalation.updateFeatures or updateOrRemove endpoints by non-administrative users; log entries reflecting sudden privilege changes for user accounts (e.g., assignment to FULLADMIN security group); Groovy script execution events in application logs.runtime or hot-deploy directories.bash, curl, wget, python, nc); evidence of reverse shell connections initiated from the OFBiz service account (PoC GitHub).Apache has released version 24.09.07 of OFBiz, which fixes this vulnerability. All users running Apache OFBiz versions prior to 24.09.07 are strongly recommended to upgrade immediately, especially given the availability of a public PoC exploit. No configuration-based workarounds have been officially documented; upgrading to 24.09.07 or later is the only confirmed remediation (Apache Advisory, GitHub Advisory). As an interim measure, organizations should restrict access to OFBiz administrative endpoints and monitor for anomalous privilege changes in user accounts.
The vulnerability was announced on the Apache security mailing list and the oss-security list on June 10, 2026, by Jacopo Cappellato on behalf of the Apache OFBiz team (oss-security). The disclosure was noted on Bluesky by security-focused accounts shortly after publication. The availability of a full-chain public PoC (including RCE) has drawn attention from the security community, with aggregators such as VulDB and exploit-intel.com tracking the vulnerability. No major vendor statements beyond the official Apache advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."