https://seclists.org/oss-sec/2026/q2/598: CVE-2026-35086: Apache OFBiz: Authenticated mote Code Execution via Unsafe Template Expansion in email services
Published May 19, 2026
·Updated
Affected Software
1 affected component
Apache OFBiz<24.09.06
Frequently Asked Questions
1
What is the severity of CVE-2026-35086?
The severity of CVE-2026-35086 is classified as moderate.
2
Which versions of Apache OFBiz are affected by CVE-2026-35086?
Apache OFBiz versions before 24.09.06 are affected by CVE-2026-35086.
3
How do I fix CVE-2026-35086?
To fix CVE-2026-35086, users are recommended to upgrade to Apache OFBiz version 24.09.06 or later.
4
What type of vulnerability is CVE-2026-35086?
CVE-2026-35086 is categorized as an improper control of generation of code vulnerability, leading to potential code injection.
5
What services in Apache OFBiz are impacted by CVE-2026-35086?
CVE-2026-35086 impacts the email services within Apache OFBiz.