Home

Description

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

PUBLISHED Reserved 2026-03-09 | Published 2026-05-19 | Updated 2026-05-19 | Assigner apache

Problem types

CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Product status

Default status
unaffected

Any version before 24.09.06
affected

Credits

Sho Odagiri of GMO Cybersecurity by Ierae, Inc. reporter

References

www.openwall.com/lists/oss-security/2026/05/19/19

lists.apache.org/thread/v2brvq1tf4q491obkxv8p7fc5qfshc08 vendor-advisory

cve.org (CVE-2026-31380)

nvd.nist.gov (CVE-2026-31380)

Download JSON