← Back to browse · API

CVE-2026-45434

Severity
CRITICAL
CVSS
9.8
EPSS
0.22429
Risk score
47.05
CISA KEV
No
PoC
No
Published
2026-05-19
Modified
2026-05-20
First seen
2026-08-06
Aliases
CNVD-2026-22766, EUVD-2026-30877, GHSA-QCXG-XCPH-9R99
Products
Apache OFBiz <24.09.06, Apache Software Foundation:Apache OFBiz 0 <24.09.06
Sources
cnvd CNVD-2026-22766
euvd EUVD-2026-30877

Description

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

References