
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50223 is a code injection vulnerability in Apache OFBiz that allows a low-privileged authenticated user with Content/DataResource editing privileges to perform FreeMarker template injection attacks leading to Remote Code Execution (RCE). It affects all Apache OFBiz versions before 24.09.07 and was publicly disclosed on June 10, 2026, by Apache security team member Jacopo Cappellato. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Apache Advisory, Github Advisory).
The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection) and stems from insufficient sanitization of user-supplied input within the Content/DataResource editing functionality of Apache OFBiz. Specifically, the application uses the FreeMarker templating engine to render content, and fails to neutralize malicious template directives injected by an authenticated user, allowing server-side template injection (SSTI). An attacker must have network access to the OFBiz instance and hold a low-privileged account with Content/DataResource editing rights; no further user interaction is required. The vulnerability was reported by researchers identified as "yi" and "Jongyeon Lee" (oss-security, Github Advisory).
Successful exploitation grants an attacker full Remote Code Execution on the affected Apache OFBiz server, resulting in high impact to confidentiality, integrity, and availability. An attacker can execute arbitrary operating system commands as the OFBiz service account, potentially enabling data exfiltration, installation of backdoors, lateral movement within the internal network, and complete system compromise. All Apache OFBiz deployments running versions prior to 24.09.07 are at risk (Apache Advisory, oss-security).
As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.657% (47th percentile), indicating a moderate near-term exploitation probability relative to other vulnerabilities. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Apache Advisory).
${"freemarker.template.utility.Execute"?new()("id")} or similar constructs that invoke Java runtime execution.${, <#, ?new()).freemarker.template.utility.Execute); access logs with POST requests to /webtools/control/main or content/data resource management endpoints containing encoded template payloads.sh, bash, cmd.exe, curl, wget, python) indicating OS command execution via template injection (oss-security).The primary remediation is to upgrade Apache OFBiz to version 24.09.07 or later, which contains the fix for this vulnerability (Apache Advisory). As an interim workaround, administrators should restrict Content/DataResource editing privileges to only fully trusted administrators, minimizing the attack surface. Additionally, monitoring for suspicious template injection patterns in content editing activities and applying network-level access controls to limit exposure of the OFBiz management interface are recommended defensive measures (oss-security).
The vulnerability was disclosed via the Apache security mailing list and oss-security by Jacopo Cappellato on June 10, 2026, crediting researchers "yi" and "Jongyeon Lee" for the report (oss-security). The disclosure was noted on Bluesky infosec community accounts shortly after publication, and the advisory was picked up by multiple vulnerability tracking services including VulDB, INCIBE-CERT, and ENISA's EUVD. No major vendor statements beyond the Apache advisory or significant independent researcher commentary have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."