CRITICAL🇵🇱 Wersja polska

CVE-2026-41919

CVSS 9.1v3.1pub. 2026-05-19

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

🤖 AI Analysis
How it works

The vulnerability results from improper neutralization of special characters used in LDAP queries (CWE-90). An attacker can inject maliciously crafted input data that modifies the logic of the LDAP query sent by the application. As a result, it is possible to bypass authentication mechanisms or gain access to data stored in the LDAP directory. The attack can be conducted remotely over the network without requiring any privileges.

Impact

An attacker can gain unauthorized access to sensitive data (confidentiality breach) and manipulate data in the LDAP directory or application logic (integrity breach).

Mitigation & patch

Apache OFBiz should be updated to version 24.09.06 or newer, which contains a patch eliminating the described vulnerability.

Who is affected

Apache OFBiz in versions prior to 24.09.06

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache Ofbiz

    APP
    Apache
    < 24.09.06
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-38856CRITICAL9.8⚠ KEVPL ✓same product

Apache OFBiz — nieautoryzowane wykonanie kodu przez błędną autoryzację

CVE-2024-32113CRITICAL9.8⚠ KEVPL ✓same product

Path Traversal w Apache OFBiz umożliwiający zdalne wykonanie kodu

CVE-2026-45434CRITICAL9.8PL ✓same product

Apache OFBiz — Auth Bypass i RCE poprzez błąd logiki zmiany hasła

CVE-2026-31986CRITICAL9.1PL ✓same product

Apache OFBiz — użycie zakodowanego na stałe klucza kryptograficznego

CVE-2025-54466CRITICAL9.8PL ✓same product

Apache OFBiz: Code Injection w pluginie scrum umożliwia RCE