CVE-2026-47342: Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges
This issue affects Apache OFBiz: before 24.09.07.
Users are recommended to upgrade to version 24.09.07, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache OFBizto a version that resolves this vulnerability.Fixed in 24.09.07
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47342?
CVE-2026-47342 has a severity rating of high with a CVSS score of 8.8.
How do I fix CVE-2026-47342?
To fix CVE-2026-47342, users should upgrade to Apache OFBiz version 24.09.07 or later.
What type of vulnerability is CVE-2026-47342?
CVE-2026-47342 is classified as a privilege escalation vulnerability.
Who is affected by CVE-2026-47342?
CVE-2026-47342 affects users of Apache OFBiz versions prior to 24.09.07.
What is the impact of CVE-2026-47342?
CVE-2026-47342 allows low-privileged authenticated users to escalate their privileges, potentially leading to unauthorized access.