CVE-2026-46586: Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code Execution
Published May 19, 2026
·Updated
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Affected Software
2 affected components
Apache OFBiz<24.09.06
Apache OFBiz<24.09.06
Event History
May 19, 2026
CVE Published
via MITRE·09:41 AM
Data Sourced
via MITRE·09:41 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-46586?
The severity of CVE-2026-46586 is rated as high, with a CVSS score of 8.8.
2
How do I fix CVE-2026-46586?
To fix CVE-2026-46586, users should upgrade to Apache OFBiz version 24.09.06 or later.
3
What type of vulnerability is CVE-2026-46586?
CVE-2026-46586 is identified as a Code Injection vulnerability and Eval Injection vulnerability.
4
What is affected by CVE-2026-46586?
CVE-2026-46586 affects Apache OFBiz versions before 24.09.06.
5
What risk does CVE-2026-46586 pose?
CVE-2026-46586 poses a risk of unauthorized authenticated Groovy code execution.