https://seclists.org/oss-sec/2026/q2/874: CVE-2026-50223: Apache OFBiz: Datasource Low-Privileged Authenticated FeMarker Template Injection Leads to mote Code Execution
Published Jun 10, 2026
·Updated
Affected Software
1 affected component
Apache OFBiz<24.09.07
Frequently Asked Questions
1
What is the severity of CVE-2026-50223?
The severity of CVE-2026-50223 is classified as moderate.
2
How do I fix CVE-2026-50223?
To fix CVE-2026-50223, upgrade Apache OFBiz to version 24.09.07 or later.
3
What are the affected versions of Apache OFBiz for CVE-2026-50223?
Apache OFBiz versions before 24.09.07 are affected by CVE-2026-50223.
4
What type of vulnerability is CVE-2026-50223?
CVE-2026-50223 is an improper control of generation of code vulnerability that allows template injection.
5
Who is impacted by CVE-2026-50223?
CVE-2026-50223 impacts low-privileged authenticated users with Content/DataResource editing privileges.