Vulnerability record · CVE-2023-49070 · published 5 December 2023
CVE-2023-49070: Apache OFBiz pre-auth RCE via legacy XML-RPC code injection
Apache · Ofbiz
Apache OFBiz before 18.12.10 ships a deprecated XML-RPC endpoint that allows code injection, resulting in remote code execution without authentication. The flaw is rated critical (CVSS 9.8) and affects internet-facing OFBiz deployments, which are commonly exposed for e-commerce and ERP functions.
Description
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network RCE with a CVSS of 9.8 and very high EPSS probability makes this an urgent patch-first issue for any exposed OFBiz instance.
What it is
Apache OFBiz before 18.12.10 ships a deprecated XML-RPC endpoint that allows code injection, resulting in remote code execution without authentication. The flaw is rated critical (CVSS 9.8) and affects internet-facing OFBiz deployments, which are commonly exposed for e-commerce and ERP functions.
Impact
An unauthenticated attacker can execute arbitrary code on the OFBiz server, leading to full compromise of the application and its data. This can enable data theft, persistence, and lateral movement into connected systems.
Attack surface
Reachable over the network via the XML-RPC interface; the CVSS vector shows no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N). Any OFBiz instance exposing the affected endpoint is directly attackable.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.95368, 99.864th percentile) and public exploit code exists (Packet Storm reference), indicating active exploitation is likely.
What to do
- Upgrade Apache OFBiz to 18.12.10 or later immediately.
- If upgrade is not possible, disable or block access to the XML-RPC endpoint at the network or reverse-proxy layer.
- Restrict internet exposure of OFBiz management and RPC interfaces to trusted networks only.
- Monitor vendor advisories and apply any follow-up patches for related OFBiz issues.
- Review server logs for signs of compromise and rotate credentials if exploitation is suspected.
Detection
- Inspect web server and OFBiz logs for POST requests to XML-RPC paths, especially from unexpected source IPs.
- Alert on outbound network connections or process creation from the OFBiz service account that are not typical for the application.
- Use the public Packet Storm exploit details to create signatures or YARA/Suricata rules for known payload patterns.
- Monitor for unexpected file writes or new processes spawned by the Java process hosting OFBiz.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-49070 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-49070), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.