8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
AI Analysis
Authentication bypass vulnerability in Apache OFBiz due to a password-change logic flaw, leading to remote code execution
Basic Information
ID
CVE-2026-45434
Source
apache
Published
May 19, 2026 at 09:40
Modified
May 19, 2026 at 13:15
Affected Product
Vendor
Apache Software Foundation
Product
Apache OFBiz
Affected Versions
Apache Software Foundation Apache OFBiz 0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Apache Software Foundation
Product
Apache OFBiz
Version
before 24.09.06