9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
AI Analysis
Unauthenticated Remote Code Execution via Default JWT Signing Key and Widget Template Injection
Basic Information
ID
CVE-2026-31986
Source
apache
Published
May 19, 2026 at 09:34
Modified
May 19, 2026 at 13:41
Affected Product
Vendor
Apache Software Foundation
Product
Apache OFBiz
Affected Versions
Apache Software Foundation Apache OFBiz 0
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
Apache Software Foundation
Product
Apache OFBiz
Version
before 24.09.06