CRITICAL🇵🇱 Wersja polska

CVE-2026-31986

CVSS 9.1v3.1pub. 2026-05-19

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

🤖 AI Analysis
How it works

The vulnerability consists of embedding a hardcoded cryptographic key directly in the Apache OFBiz application source code. Because the key is identical in all installations, a person with knowledge of it (e.g., through source code analysis or previous disclosures) can exploit it without needing to guess it. The attack vector is network-based, requires no authentication or user interaction, which significantly lowers the entry threshold for a potential attacker.

Impact

An attacker can gain unauthorized access to protected data (breach of confidentiality) and potentially modify data secured with this key (breach of integrity). According to the CVSS vector, the vulnerability does not directly affect system availability.

Mitigation & patch

Apache OFBiz must be immediately updated to version 24.09.06 or newer, which eliminates the vulnerability. After updating, it is recommended to revoke and rotate the cryptographic keys and certificates that may have been compromised.

Who is affected

Apache OFBiz in all versions before 24.09.06

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache Ofbiz

    APP
    Apache
    < 24.09.06
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-38856CRITICAL9.8⚠ KEVPL ✓same product

Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację

CVE-2024-32113CRITICAL9.8⚠ KEVPL ✓same product

Path Traversal w Apache OFBiz umożliwiający zdalne wykonanie kodu

CVE-2026-45434CRITICAL9.8PL ✓same product

Apache OFBiz — Auth Bypass i RCE poprzez błąd logiki zmiany hasła

CVE-2026-41919CRITICAL9.1PL ✓same product

LDAP Injection w Apache OFBiz umożliwiający nieautoryzowany dostęp

CVE-2025-54466CRITICAL9.8PL ✓same product

Apache OFBiz: Code Injection w pluginie scrum umożliwia RCE