Aretiq.AI[verified]@AretiqAIPoC
CVE‑2026‑45434 in Apache OFBiz allows an authentication bypass via a single HTTP request that results in remote command execution; a PoC and detection rules have been released.
モーくん🐮|WordPress × セキュリティ[verified]@accell_mo_kunDisclosure
The tweet announces a newly disclosed Apache OFBiz vulnerability (CVE‑2026‑45434) that provides remote code execution and authentication bypass, noting Google’s AI‑based discovery but offering no PoC, exploit code, or patch details.
kokumօtօ[verified]@__kokumotoDisclosure
The text discloses a critical CVE-2026-45434 in Apache OFBiz, describing it as an RCE stemming from a logic flaw in the password reset function, without mentioning PoC code, exploits, or active exploitation.
IntegSec[verified]@integ_secGeneral
The provided text highlights a remote code execution vulnerability in Apache OFBiz's password‑change logic, but it offers no PoC, exploit code, active exploitation evidence, patch details, or technical specifics beyond the RCE claim.
UNDERCODE NEWS[verified]@UndercodeNewsDisclosure
The tweet announces a newly disclosed Apache OFBiz authentication bypass (CVE-2026-45434) that can lead to full remote code execution on unpatched ERP systems, without mentioning PoC, exploit code, or mitigation.
Roberto A. Foglietta 🐧🐧@robang74v2Disclosure
The text announces new critical vulnerabilities in Apache OFBiz and NGINX that allow authentication bypass and remote code execution, with research links potentially offering further details or PoC.
Cyber Edition@CyberEditionPatch
A critical RCE flaw in Apache OFBiz (CVE-2026-45434) permits authentication bypass and is publicly demonstrated; update to 24.09.06 immediately to mitigate the risk.
iototsecnews@iototsecnewsDisclosure
The article announces a critical authentication‑bypass and remote code execution flaw in Apache OFBiz (CVE‑2026‑45434), explains how mishandled password‑change logic and missing safeguards allow execution of arbitrary commands, and notes that a fix has been released.