Security Advisory

CVE-2026-35086

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-19 09:36:00
Last updated 2026-05-20 03:55:19
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.