August 27, 2024 · Applied Cybernetics Group
CVE-2024-38856 — Apache OFBiz
Apache OFBiz Incorrect Authorization Vulnerability
- Added to KEV
2024-08-27- Federal due date
2024-09-17- Vendor
- Apache
- Product
- OFBiz
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-38856
CISA short description
Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.