CVE-2026-29226
Description
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Low-privilege SSRF in Apache OFBiz Content component allows unauthorized server requests; fixed in 24.09.06.
Vulnerability
Server-Side Request Forgery (SSRF) vulnerability exists in the Apache OFBiz Content component operations. Affected versions are Apache OFBiz before 24.09.06. The issue allows an authenticated user with low privileges to craft requests that trigger server-side HTTP requests to arbitrary destinations [1].
Exploitation
An attacker must have low-privilege authenticated access to an Apache OFBiz instance. By manipulating input to the Content component, the attacker can force the server to make outgoing requests to attacker-controlled URLs or internal resources. No special network position or user interaction beyond standard low-privilege login is required [1].
Impact
Successful exploitation enables the attacker to perform SSRF, sending HTTP requests from the OFBiz server to internal or external systems. This can lead to information disclosure, access to internal services, or further network reconnaissance. The attacker gains the ability to probe and potentially interact with resources behind the server’s firewall [1].
Mitigation
Upgrade to Apache OFBiz version 24.09.06, which fixes the vulnerability. The fix was released on 2026-05-19. No workarounds have been disclosed in the available references. The vulnerability is not known to be listed in the CISA Known Exploited Vulnerabilities catalog as of publication date [1].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- lists.apache.org/thread/6707wys8jxzmowxggn4cmtwwk9ygl2trnvdMailing ListVendor Advisory
- www.openwall.com/lists/oss-security/2026/05/19/16nvd
News mentions
0No linked articles in our index yet.