Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4391 articles · 196851 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-31986PATCHED
apache · ofbiz

Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection

Description

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Affected Products

VendorProductVersions
apacheofbiz0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheofbizcert_advisory90%

References

  • https://lists.apache.org/thread/2hl9xoqm8tq8b22x6vnmtp7tg3opcqgc(vendor-advisory)

Related News (5 articles)

Tier D
Help Net Security19d ago
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
→ No new info (linked only)
Tier D
Heise Security97d ago
Sicherheitsupdate: Hartkodierter Schlüssel ermöglicht Zugriffe auf Apache OFBiz
→ No new info (linked only)
Tier C
oss-security97d ago
CVE-2026-31986: Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection
→ No new info (linked only)
Tier B
BSI Advisories98d ago
[NEU] [hoch] Apache OFBiz: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB98d ago
CVE-2026-31986 | Apache OFBiz up to 24.09.05 hard-coded key
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
24.09.06
CWECWE-321, CWE-94
PublishedMay 19, 2026
Last enriched97d agov3
Trending Score8
Source articles5
Independent5
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-53434EXP
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Trending: 40
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 34
CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 34
HIGHCVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Trending: 34
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 34

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 19, 2026
Discovered by ZDM
May 19, 2026
Updated: affectedVersions, severity
May 19, 2026
Patch Available
May 19, 2026
Updated: cweIds
May 20, 2026

Version History

v3
Last enriched 97d ago
v3Tier D97d ago

Updated description with new technical details, added CWE-94, and marked the vulnerability as actively exploited with an exploit available.

cweIds
via Heise Security
v2Tier C98d ago

Updated affected versions to include 24.09.05, changed severity to HIGH, and noted that no exploit is available.

affectedVersionsseverity
via VulDB
v198d ago

Initial creation