VYPR
Medium severity6.5NVD Advisory· Published May 19, 2026· Updated May 19, 2026

CVE-2026-31378

CVE-2026-31378

Description

Improper Input Validation vulnerability in Apache OFBiz.

This issue affects Apache OFBiz: before 24.09.06.

Users are recommended to upgrade to version 24.09.06, which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Apache OFBiz before 24.09.06 contains an improper input validation vulnerability allowing remote code execution via JSON attribute override and URL allowlist bypass.

Vulnerability

Overview

CVE-2026-31378 is an improper input validation vulnerability in Apache OFBiz, affecting versions prior to 24.09.06. The flaw stems from insufficient validation of JSON attributes and a bypass of the URL allowlist, enabling an attacker to override critical attributes and bypass security controls [1].

Exploitation

An attacker with network access to an affected OFBiz instance can send specially crafted HTTP requests that exploit the JSON attribute override and URL allowlist bypass. No authentication is required, making the attack surface broad. The vulnerability can be triggered without prior knowledge of the system, leading to remote code execution [1].

Impact

Successful exploitation allows an attacker to execute arbitrary code on the server, potentially leading to full compromise of the OFBiz application and underlying system. This includes data theft, service disruption, and further lateral movement within the network.

Mitigation

The Apache OFBiz project has released version 24.09.06, which addresses the issue by properly validating JSON inputs and enforcing the URL allowlist. Users are strongly advised to upgrade immediately. No workarounds have been published. The vulnerability was reported by Sho Odagiri of GMO Cybersecurity by Ierae, Inc. [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.