VYPR
Critical severity9.8NVD Advisory· Published Mar 22, 2021· Updated Jun 17, 2026

CVE-2021-26295

CVE-2021-26295

Description

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Apache/Ofbiz3 versions
    cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*:*range: <17.12.06
    • (no CPE)range: <17.12.06
    • (no CPE)range: Apache OFBiz 17.12.01 to 17.12.05

Patches

Vulnerability mechanics

References

13

News mentions

0

No linked articles in our index yet.