Security Advisory

CVE-2026-45434

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-19 09:40:26
Last updated 2026-05-20 15:34:15
Assigner apache
CVSS score not scored
State PUBLISHED

Description

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.