CVE-2026-41919: Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction
Published May 19, 2026
·Updated
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Affected Software
2 affected components
Apache Apache OFBiz<24.09.06
Apache OFBiz<24.09.06
Event History
May 19, 2026
CVE Published
via MITRE·09:36 AM
Data Sourced
via MITRE·09:36 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-41919?
CVE-2026-41919 has a critical severity rating of 9.1 on the CVSS scale.
2
How do I fix CVE-2026-41919?
To fix CVE-2026-41919, upgrade to Apache OFBiz version 24.09.06 or later.
3
What does CVE-2026-41919 affect?
CVE-2026-41919 affects Apache OFBiz prior to version 24.09.06.
4
What type of vulnerability is CVE-2026-41919?
CVE-2026-41919 is an authentication bypass vulnerability caused by improper neutralization of special elements in LDAP queries.
5
What are the potential impacts of CVE-2026-41919?
The potential impacts of CVE-2026-41919 include unauthorized access to sensitive data due to LDAP injection.