CVE-2026-46586Patch(apache / ofbiz)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apache ofbiz systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-95

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ofbiz

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-21)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ofbiz

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-19: 1Mentions · 2026-05-21: 2Patch / Workaround · 2026-05-21: 2Technical Details · 2026-05-19: 1Technical Details · 2026-05-21: 205-1905-21
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-191
Disclosure1
2026-05-212
Patch2
Full discourse3 posts
  • selva@SelvaKtm2
    Patch

    Apache OFBiz Fixes CVE-2026-46586 Groovy Code Execution Vulnerability https://thecybrdef.com/apache-ofbiz-fixes-cve-2026-46586-groovy-code-execution-vulnerability/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    The article announces that Apache OFBiz has released a fix for CVE-2026-46586, a Groovy code execution vulnerability, but does not mention any PoC, exploit tool, or evidence of active exploitation.

    0000035
    5 followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    Apache OFBiz Fixes CVE-2026-46586 Groovy Code Execution Vulnerability https://thecybrdef.com/apache-ofbiz-fixes-cve-2026-46586-groovy-code-execution-vulnerability/ #Cyberupdates #Cybertechnews #Cybersecurity

    Post summary

    Apache OFBiz has released a patch for CVE-2026-46586, a Groovy code execution vulnerability, with no mention of exploit code or active attacks.

    0000045
    9 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-46586 Code Injection and Eval Injection Vulnerability in Apache OFBiz B... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-46586 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces a code and eval injection vulnerability in Apache OFBiz, but provides no PoC, exploit code, or patch details.

    0000059
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheofbiz---

Explore more