CVE-2026-31986Patch(apache / ofbiz)

MEDIUMCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache ofbiz systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ofbiz

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 3 mentions (2026-08-05); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
ofbiz

Deep dive

Activity timeline9 mentions / 5d
01223Mentions · 2026-05-19: 2Mentions · 2026-05-21: 2Mentions · 2026-08-05: 3Mentions · 2026-08-06: 1Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-08-06: 1Exploit Tool / Code · 2026-08-06: 1Patch / Workaround · 2026-05-19: 2Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-08-06: 1Technical Details · 2026-05-19: 2Technical Details · 2026-05-21: 2Technical Details · 2026-08-05: 3Technical Details · 2026-08-06: 105-1905-2108-0508-0610-02
Signal classification3 categories
Patch
450.0%
Disclosure
337.5%
Exploit
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-192
Patch2
2026-05-212
Patch2
2026-08-053
Disclosure3
2026-08-061
Exploit1
Full discourse9 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Apache OFBiz Hard-Coded Cryptographic Key Vulnerability (CVE-2026-31986) Apache OFBiz contains a hard-coded cryptographic key vulnerability that may allow attackers to gain unauthorized access, expose sensitive data, or tamper with application data remotely. 👉 Affected: Apache OFBiz < 24.09.06 | Fix: Upgrade to Apache OFBiz 24.09.06 immediately

    Post summary

    Apache OFBiz versions prior to 24.09.06 suffer a hard‑coded key vulnerability; users are urged to upgrade to the patched release to remediate.

    0002085
    255 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    Apache OFBiz users: CVE-2026-31986 (CVSS 9.1) involves a hard-coded cryptographic key and affects versions before 24.09.06. Upgrade to 24.09.06 to address the issue. Details: https://nvd.nist.gov/vuln/detail/CVE-2026-31986 Learn more at http://adkcyber.com via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning

    Post summary

    The post announces CVE-2026-31986—a hard‑coded key vulnerability in Apache OFBiz—and recommends upgrading to 24.09.06, without providing exploit or PoC details.

    0001060
    80 followersView on X
  • IntegSec@integ_sec

    CVE-2026-31986: Apache OFBiz Hard-Coded Cryptographic Key Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04z499F0

    0000031
    35 followersView on X
  • Tony Cleal CISSP, SSCP, CISA, CISM, GCIH@tony_cleal
    Exploit

    https://www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/

    Post summary

    The article discloses CVE‑2026‑31986, a pre‑authentication RCE in Bonita Ofbiz, provides PoC and exploit code, details the technical aspects and CVSS score, and notes a vendor patch, but does not report active exploitation.

    0000051
    992 followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers https://www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    A new pre‑authentication remote code execution vulnerability (CVE‑2026‑31986) impacting Bonita and OFBiz servers has been disclosed; no PoC, exploit, or patch information is provided.

    000001.9K
    195.2K followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers: An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker… https://www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/?utm_source=dlvr.it&utm_medium=twitter https://t.co/BIRIKy2XYk

    Post summary

    The article announces a new pre‑authentication RCE vulnerability (CVE‑2026‑31986) affecting Bonita and OFBiz servers, explaining how an unauthenticated web request can trigger internal API execution, but it does not discuss PoC, exploit tools, active attacks, or patches.

    0000067
    2.3K followersView on X
  • Help Net Security@helpnetsecurity
    Disclosure

    Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers - https://www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/ - @novee_security @BlackHatEvents #BlackHat #BHUSA #CyberSecurity #CyberSecurityNews #InfoSec #RCE https://t.co/tAcWB3Lo65

    Post summary

    The tweet announces a pre‑authentication remote code execution vulnerability (CVE‑2026‑31986) affecting Bonita and OFBiz Java servers, providing basic technical details but no patch, exploit, or PoC information.

    00000534
    60.1K followersView on X
  • selva@SelvaKtm2
    Patch

    Patch Apache OFBiz: CVE-2026-31986 Unauthenticated RCE Flaw https://thecybrdef.com/apache-ofbiz-cve-2026-31986-unauthenticated-rce/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    The message announces that Apache OFBiz is affected by CVE-2026-31986, an unauthenticated remote code execution vulnerability, and that a patch is available.

    0000037
    5 followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    Patch Apache OFBiz: CVE-2026-31986 Unauthenticated RCE Flaw https://thecybrdef.com/apache-ofbiz-cve-2026-31986-unauthenticated-rce/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    The post announces an Apache OFBiz patch for CVE-2026-31986, which is an unauthenticated remote code execution flaw, and does not provide PoC or exploit details.

    0000053
    9 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheofbiz---

Explore more