← Vulnerability feed

Vulnerability record · CVE-2021-26295 · published 22 March 2021

CVE-2021-26295: Apache OFBiz unsafe deserialization allows unauthenticated takeover

Apache · Ofbiz

Apache OFBiz before 17.12.06 performs unsafe deserialization of untrusted data, matching CWE-502. An unauthenticated attacker can exploit this to take over the application. With a CVSS 3.1 base score of 9.8 and an EPSS 30-day probability near 0.98, this is a high-urgency remote code execution class flaw.

9.8 CVSS 3.1 Critical EPSS 98% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, near-maximum EPSS, and public exploit code make this an urgent remote takeover risk.

What it is

Apache OFBiz before 17.12.06 performs unsafe deserialization of untrusted data, matching CWE-502. An unauthenticated attacker can exploit this to take over the application. With a CVSS 3.1 base score of 9.8 and an EPSS 30-day probability near 0.98, this is a high-urgency remote code execution class flaw.

Impact

Successful exploitation gives the attacker full control of the Apache OFBiz instance, consistent with the CVSS impact ratings of high confidentiality, integrity and availability. This can lead to data theft, tampering and service disruption.

Attack surface

The flaw is network-reachable with no privileges and no user interaction required (AV:N/AC:L/PR:N/UI:N). Public exploit material references a SOAP/Java deserialization path, indicating the attack is delivered over the exposed service interface.

Exploitation

CISA KEV does not list this CVE, but EPSS is 0.97822 (99.9th percentile) and public references are tagged Exploit, indicating working exploit code is available. No ransomware group is documented as using it in this record.

What to do

  • Upgrade Apache OFBiz to 17.12.06 or later; this is the primary fix.
  • If immediate upgrade is not possible, restrict network access to OFBiz endpoints to trusted hosts only.
  • Disable or block unnecessary SOAP/deserialization-exposing interfaces until patched.
  • Monitor vendor and Apache mailing list advisories for the official patch guidance.
  • Treat any internet-facing OFBiz instance as high risk and prioritize it for remediation.

Detection

  • Inspect web and application logs for SOAP requests containing serialized Java objects or unusual content types.
  • Alert on unexpected child processes or command execution spawned by the OFBiz Java process.
  • Monitor for outbound connections from OFBiz hosts to unfamiliar external addresses.
  • Review OFBiz access logs for anomalous request patterns from unauthenticated sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/162104/Apache-OFBiz-SOAP-Java-Deserialization.html ExploitThird Party AdvisoryVDB Entry
https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723236d1c73f43ff0%40%3Cdev.ofbiz.apache.org
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/r3c1802eaf34aa78a61b4e8e044c214bc94accbd28a11f3a276586a31%40%3Cuser.ofbiz.apache.or Mailing ListPatchVendor Advisory
https://lists.apache.org/thread.html/r3ee005dd767cd83f522719423f5e7dd316f168ddbd1dc51a13d4e244%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/r6e4579c4ebf7efeb462962e359501c6ca4045687f12212551df2d607%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199f42e36efb8d735%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a38224e956295ce%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/rc9bd0d3d794dc370bc70585960841868cb29b92dcc80552b84ca2599%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rec5e9fdcdca13099cfb29f632333f44ad1dd60d90f67b90434e4467a%40%3Cdev.ofbiz.apache.org
https://lists.apache.org/thread.html/reccf8c8a58337ce7c035495d3d82fbc549e97036a9789a2a7d9cccf6%40%3Cdev.ofbiz.apache.org
http://packetstormsecurity.com/files/162104/Apache-OFBiz-SOAP-Java-Deserialization.html ExploitThird Party AdvisoryVDB Entry
https://lists.apache.org/thread.html/r078351a876ed284ba667b33aba29428d7308a5bd4df78f14a3df6661%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/r0d97a3b7a14777b9e9e085b483629d2774343c4723236d1c73f43ff0%40%3Cdev.ofbiz.apache.org
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/r3c1802eaf34aa78a61b4e8e044c214bc94accbd28a11f3a276586a31%40%3Cuser.ofbiz.apache.or Mailing ListPatchVendor Advisory
https://lists.apache.org/thread.html/r3ee005dd767cd83f522719423f5e7dd316f168ddbd1dc51a13d4e244%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/r6e4579c4ebf7efeb462962e359501c6ca4045687f12212551df2d607%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rab718cfe6468085d7560c0c1ae816841e175886199f42e36efb8d735%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rbe512e5ccd6b11169c6379daa1234bc805f3d53c5a38224e956295ce%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/rc9bd0d3d794dc370bc70585960841868cb29b92dcc80552b84ca2599%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rec5e9fdcdca13099cfb29f632333f44ad1dd60d90f67b90434e4467a%40%3Cdev.ofbiz.apache.org
https://lists.apache.org/thread.html/reccf8c8a58337ce7c035495d3d82fbc549e97036a9789a2a7d9cccf6%40%3Cdev.ofbiz.apache.org

Track CVE-2021-26295 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2021-26295), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.