CVE-2026-35086: Apache OFBiz: Authenticated Remote Code Execution via Unsafe Template Expansion in email services
Published May 19, 2026
·Updated
Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Affected Software
2 affected components
Apache Apache OFBiz<24.09.06
Apache OFBiz<24.09.06
Event History
May 19, 2026
CVE Published
via MITRE·09:36 AM
Data Sourced
via MITRE·09:36 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35086?
CVE-2026-35086 has a medium severity rating of 6.5 on the CVSS scale.
2
How do I fix CVE-2026-35086?
To fix CVE-2026-35086, users should upgrade to Apache OFBiz version 24.09.06 or later.
3
What type of vulnerability is CVE-2026-35086?
CVE-2026-35086 is a code injection vulnerability in the email services of Apache OFBiz.
4
What impact does CVE-2026-35086 have?
CVE-2026-35086 allows authenticated attackers to execute remote code through unsafe template expansion.
5
Which versions of Apache OFBiz are affected by CVE-2026-35086?
CVE-2026-35086 affects all versions of Apache OFBiz prior to 24.09.06.