CVE-2026-31379: Apache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog Manager
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31379?
CVE-2026-31379 has a medium severity rating of 6.1 according to the CVSS 3.1 scoring.
How can I fix CVE-2026-31379?
To fix CVE-2026-31379, ensure you upgrade to Apache OFBiz version 24.09 or later.
What types of vulnerabilities are associated with CVE-2026-31379?
CVE-2026-31379 is associated with Cross-site Scripting (XSS), Path Traversal, and Code Injection vulnerabilities.
What kind of attacks can result from CVE-2026-31379?
CVE-2026-31379 can lead to arbitrary file writes, stored XSS, and potential remote code execution (RCE) in the Catalog Manager.
Which version of Apache OFBiz is affected by CVE-2026-31379?
CVE-2026-31379 affects all versions of Apache OFBiz before 24.09.