CVE-2026-45434Disclosure(apache / ofbiz)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache ofbiz systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ofbiz

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 12 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 12 signals
  • Disclosure: 8 classified signals
  • Peaked 4d ago at 6 mentions (2026-05-21); latest day: 1
  • 12 total mentions across 7 days

Affected systems

Vendors
Products
ofbiz

Deep dive

Activity timeline12 mentions / 7d
02356Mentions · 2026-05-19: 1Mentions · 2026-05-20: 1Mentions · 2026-05-21: 6Mentions · 2026-05-22: 1Mentions · 2026-05-26: 1Mentions · 2026-05-28: 1Mentions · 2026-06-18: 1PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-21: 2Exploit Tool / Code · 2026-05-20: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 6Technical Details · 2026-05-22: 1Technical Details · 2026-05-26: 1Technical Details · 2026-05-28: 1Technical Details · 2026-06-18: 105-1905-2005-2105-2205-2605-2806-18
Signal classification4 categories
Disclosure
866.7%
Patch
216.7%
PoC
18.3%
General
18.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-191
Disclosure1
2026-05-201
PoC1
2026-05-216
Disclosure5Patch1
2026-05-221
Disclosure1
2026-05-261
Patch1
2026-05-281
Disclosure1
2026-06-181
General1
Full discourse12 posts
  • Aretiq.AI@AretiqAI
    PoC

    New N-day research: CVE-2026-45434 — Apache OFBiz Authentication Bypass → RCE A single HTTP request bypasses forced password-change restrictions and achieves OS command execution. Full analysis, detection rules, and PoC: https://aretiq.ai/research/3

    Post summary

    CVE‑2026‑45434 in Apache OFBiz allows an authentication bypass via a single HTTP request that results in remote command execution; a PoC and detection rules have been released.

    0191513818.7K
    195 followersView on X
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Disclosure

    Apache OFBizにRCE+認証バイパス(CVE-2026-45434)が出たモー🐮 しかも昨日、GoogleがAIモデルでゼロデイ発見・武器化してた痕跡も確認… 「AIで攻める時代」のWeb制作者の備え、4ツイートでまとめるモー👇 #Webフリーランス #駆け出しエンジニアと繋がりたい https://t.co/rUwXrWNULj

    Post summary

    The tweet announces a newly disclosed Apache OFBiz vulnerability (CVE‑2026‑45434) that provides remote code execution and authentication bypass, noting Google’s AI‑based discovery but offering no PoC, exploit code, or patch details.

    10020113
    759 followersView on X
  • Roberto A. Foglietta 🐧🐧@robang74v2
    Disclosure

    NGIX IS DONE, APACHE AS WELL New N-day research: CVE-2026-45434 — Apache OFBiz Authentication Bypass → RCE ~> https://aretiq.ai/research/3 Critical NGINX Vulnerability Lets Hackers Launch Remote Code Execution (RCE) Attacks. ~> https://gbhackers.com/critical-nginx-vulnerability/ *** https://t.co/bXGDzxr0yN

    Post summary

    The text announces new critical vulnerabilities in Apache OFBiz and NGINX that allow authentication bypass and remote code execution, with research links potentially offering further details or PoC.

    00111153
    128 followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    Apache OFBizに重大(Critical)な脆弱性。CVE-2026-45434はパスワードリセット機能のロジック不備に起因する遠隔コード実行。その他複数脆弱性と併せ修正。 https://securityonline.info/apache-ofbiz-rce-vulnerability-authentication-bypass-cve-2026-45434/

    Post summary

    The text discloses a critical CVE-2026-45434 in Apache OFBiz, describing it as an RCE stemming from a logic flaw in the password reset function, without mentioning PoC code, exploits, or active exploitation.

    00030727
    7.6K followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🔥 Critical Apache OFBiz flaw CVE-2026-45434 lets attackers bypass auth and gain full RCE. Public PoC is already out, and default demo creds make exposed servers easy targets. Update to 24.09.06 immediately. Read more https://thecyberedition.com/apache-ofbiz-rce-flaw-cve-2026-45434-enables-auth-bypass-attacks/ #CyberSecurity #RCE

    Post summary

    A critical RCE flaw in Apache OFBiz (CVE-2026-45434) permits authentication bypass and is publicly demonstrated; update to 24.09.06 immediately to mitigate the risk.

    00020115
    729 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-45434: Apache OFBiz Password-Change Logic Flaw Leading to Remote Code Execution - What It Means for Your Business and How to Respond https://hubs.li/Q04lSytM0

    Post summary

    The provided text highlights a remote code execution vulnerability in Apache OFBiz's password‑change logic, but it offers no PoC, exploit code, active exploitation evidence, patch details, or technical specifics beyond the RCE claim.

    0000033
    31 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache OFBiz の脆弱性 CVE-2026-45434 が FIX:PW 変更処理の不備による認証回避と RCE https://iototsecnews.jp/2026/05/21/apache-ofbiz-rce-flaw-abuses-password-change-restrictions-for-authentication-bypass/ 今回の脆弱性 CVE-2026-45434 の原因は、パスワード変更が必要な状態を、プログラムがエラー (認証失敗) として正しく扱わなかったことにあります。さらに、その変更フラグの判断を安全なデータベースからではなく、ユーザーが自由に書き換えられる通信データから直接読み込んでしまったことも大きな問題です。これらに加え、プログラムを実行する機能に権限チェックや安全な制限が欠落しているため、悪意のある命令がそのまま実行できる状態になっています。ご利用のチームは、十分に ご注意ください。 #Apache #CVE202645434 #OFBiz #Vulnerability

    Post summary

    The article announces a critical authentication‑bypass and remote code execution flaw in Apache OFBiz (CVE‑2026‑45434), explains how mishandled password‑change logic and missing safeguards allow execution of arbitrary commands, and notes that a fix has been released.

    0000072
    489 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🚨 CVE-2026-45434 — Apache OFBiz, CVSS 9.8. Auth bypass via password-change logic flaw leads to full RCE. No auth required, network exploitable. Upgrade to 24.09.06 now. https://secalerts.co/vulnerability/CVE-2026-45434

    Post summary

    Apache OFBiz CVE-2026-45434 is a high‑severity authentication bypass that enables remote code execution; installing version 24.09.06 resolves the issue. No evidence of active exploitation is provided.

    0000082
    826 followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-45434: Apache OFBiz Auth Bypass Leads to Critical RCE https://thecybrdef.com/cve-2026-45434-apache-ofbiz-auth-bypass-rce/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    The article announces CVE-2026-45434 as a critical authentication bypass that allows remote code execution in Apache OFBiz.

    0000038
    5 followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Disclosure

    🚨 Apache OFBiz Critical Authentication Bypass (#CVE-2026-45434) Enables Full Remote Code Execution on Unpatched ERP Systems -Fact Checker: ✅: 2 ❌: 1 || 2/3 http://undercodenews.com/apache-ofbiz-critical-authentication-bypass-cve-2026-45434-enables-full-remote-code-execution-on-unpatched-erp-systems/

    Post summary

    The tweet announces a newly disclosed Apache OFBiz authentication bypass (CVE-2026-45434) that can lead to full remote code execution on unpatched ERP systems, without mentioning PoC, exploit code, or mitigation.

    0000052
    867 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-45434: Apache OFBiz Auth Bypass Leads to Critical RCE https://thecybrdef.com/cve-2026-45434-apache-ofbiz-auth-bypass-rce/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    The post announces a new vulnerability (CVE‑2026‑45434) in Apache OFBiz, describing an authentication bypass that enables critical remote code execution, but provides no PoC, exploit, patch, or exploitation evidence.

    0000058
    9 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-45434 Improper Authentication in Apache OFBiz Before 24.09.06 Leading to Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45434

    Post summary

    The text announces CVE-2026-45434, an improper authentication flaw in Apache OFBiz before 24.09.06 that permits remote code execution.

    0000058
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheofbiz---

Explore more