Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2982 articles · 185103 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-31986PATCHED
apache · ofbiz

Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection

Description

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Affected Products

VendorProductVersions
apacheofbiz0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheofbizcert_advisory90%

References

  • https://lists.apache.org/thread/2hl9xoqm8tq8b22x6vnmtp7tg3opcqgc(vendor-advisory)

Related News (5 articles)

Tier D
Help Net Security3d ago
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
→ No new info (linked only)
Tier D
Heise Security80d ago
Sicherheitsupdate: Hartkodierter Schlüssel ermöglicht Zugriffe auf Apache OFBiz
→ No new info (linked only)
Tier C
oss-security81d ago
CVE-2026-31986: Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injection
→ No new info (linked only)
Tier B
BSI Advisories81d ago
[NEU] [hoch] Apache OFBiz: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB81d ago
CVE-2026-31986 | Apache OFBiz up to 24.09.05 hard-coded key
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
24.09.06
CWECWE-321, CWE-94
PublishedMay 19, 2026
Last enriched80d agov3
Trending Score46
Source articles5
Independent5
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-41293EXP
Apache Tomcat: HTTP/2 request headers not validated
Trending: 64
NONECVE-2026-43515EXP
Apache Tomcat: Security constraints not correctly applied
Trending: 56
HIGHCVE-2026-41284EXP
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
Trending: 55
HIGHCVE-2026-42498EXP
Apache Tomcat: WebSocket authentication header exposure
Trending: 55
CRITICALCVE-2026-43512
Apache Tomcat: Digest authenticator will authenticate any unknown user
Trending: 53

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 19, 2026
Discovered by ZDM
May 19, 2026
Updated: affectedVersions, severity
May 19, 2026
Patch Available
May 19, 2026
Updated: cweIds
May 20, 2026

Version History

v3
Last enriched 80d ago
v3Tier D80d ago

Updated description with new technical details, added CWE-94, and marked the vulnerability as actively exploited with an exploit available.

cweIds
via Heise Security
v2Tier C81d ago

Updated affected versions to include 24.09.05, changed severity to HIGH, and noted that no exploit is available.

affectedVersionsseverity
via VulDB
v181d ago

Initial creation