9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
AI Analysis
LDAP Injection vulnerability allowing authentication bypass in Apache OFBiz before version 24.09.06
Basic Information
ID
CVE-2026-41919
Source
apache
Published
May 19, 2026 at 09:36
Modified
May 19, 2026 at 13:41
Affected Product
Vendor
Apache Software Foundation
Product
Apache OFBiz
Affected Versions
Apache Software Foundation Apache OFBiz 0
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
Apache Software Foundation
Product
Apache OFBiz
Version
before 24.09.06