CVE-2026-31380: Apache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization Bypass
Published May 19, 2026
·Updated
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Affected Software
2 affected components
Apache Apache OFBiz<24.09.06
Apache OFBiz<24.09.06
Event History
May 19, 2026
CVE Published
via MITRE·09:24 AM
Data Sourced
via MITRE·09:24 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31380?
The severity of CVE-2026-31380 is medium, with a CVSS score of 6.5.
2
How do I fix CVE-2026-31380?
To fix CVE-2026-31380, upgrade to Apache OFBiz version 24.09.06 or later.
3
What type of vulnerability is CVE-2026-31380?
CVE-2026-31380 is an Expression Language Injection vulnerability.
4
Which versions of Apache OFBiz are affected by CVE-2026-31380?
CVE-2026-31380 affects Apache OFBiz versions before 24.09.06.
5
What is the impact of CVE-2026-31380?
CVE-2026-31380 may allow an attacker to exploit the system through FreeMarker SSTI by bypassing parameter sanitization.