← Vulnerability feed

Vulnerability record · CVE-2021-29200 · published 27 April 2021

CVE-2021-29200: Apache OFBiz unsafe deserialization allows unauthenticated RCE

Apache · Ofbiz

Apache OFBiz before 17.12.07 performs unsafe deserialization of untrusted data (CWE-502), and the vendor states an unauthenticated user can achieve remote code execution. The flaw is network-reachable with no privileges or user interaction required, making it a severe pre-auth RCE risk for exposed OFBiz instances.

9.8 CVSS 3.1 Critical EPSS 55% · top 1.0% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
17 Jun 2026Last modified by NVD

Description

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityPre-authentication network RCE with CVSS 9.8 and very high EPSS percentile, though not yet in KEV.

What it is

Apache OFBiz before 17.12.07 performs unsafe deserialization of untrusted data (CWE-502), and the vendor states an unauthenticated user can achieve remote code execution. The flaw is network-reachable with no privileges or user interaction required, making it a severe pre-auth RCE risk for exposed OFBiz instances.

Impact

An unauthenticated attacker can execute arbitrary code on the OFBiz server, leading to full compromise of confidentiality, integrity and availability.

Attack surface

Reached over the network via the vulnerable deserialization endpoint; the CVSS vector (AV:N/AC:L/PR:N/UI:N) and the description both indicate no authentication and no user interaction are needed.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high (0.5537, ~99th percentile), indicating substantial predicted exploitation activity; references include patch and vendor advisory links.

What to do

  • Upgrade Apache OFBiz to 17.12.07 or later, which the vendor references identify as the fixed release.
  • If immediate upgrade is not possible, restrict network access to OFBiz instances to trusted networks and place them behind authentication-aware proxies.
  • Monitor the OFBiz commit and announcement mailing lists referenced in the advisory for any further fixes or backports.
  • Review and harden any Java deserialization entry points in custom OFBiz code and dependencies.
  • Treat any internet-exposed OFBiz instance as potentially compromised and check for signs of intrusion.

Detection

  • Monitor OFBiz application and web server logs for unexpected deserialization errors or unusual request payloads to OFBiz endpoints.
  • Alert on outbound network connections or child processes spawned by the OFBiz Java process, which may indicate post-exploitation.
  • Hunt for known Java deserialization gadget signatures (e.g., ysoserial-style payload markers) in HTTP request bodies.
  • Baseline normal OFBiz request patterns and flag anomalous large or binary-encoded POST bodies.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2021/04/27/4 Mailing ListPatchThird Party Advisory
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/r708351f1a8af7adb887cc3d8a92bed8fcbff4a9e495e69a9ee546fda%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cannounce.apache.org%
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cuser.ofbiz.apache.or
http://www.openwall.com/lists/oss-security/2021/04/27/4 Mailing ListPatchThird Party Advisory
https://lists.apache.org/thread.html/r108a964764b8bd21ebd32ccd4f51c183ee80a251c105b849154a8e9d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/r708351f1a8af7adb887cc3d8a92bed8fcbff4a9e495e69a9ee546fda%40%3Cnotifications.ofbiz.
https://lists.apache.org/thread.html/rbe8439b26a71fc3b429aa793c65dcc4a6e349bc7bb5010746a74fa1d%40%3Ccommits.ofbiz.apache
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cannounce.apache.org%
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cdev.ofbiz.apache.org Mailing ListVendor Advisory
https://lists.apache.org/thread.html/re21d25d9fb89e36cea910633779c23f144b9b60596b113b7bf1e8097%40%3Cuser.ofbiz.apache.or

Track CVE-2021-29200 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2021-29200), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.