← Vulnerability feed

Vulnerability record · CVE-2023-49070 · published 5 December 2023

CVE-2023-49070: Apache OFBiz pre-auth RCE via legacy XML-RPC code injection

Apache · Ofbiz

Apache OFBiz before 18.12.10 ships a deprecated XML-RPC endpoint that allows code injection, resulting in remote code execution without authentication. The flaw is rated critical (CVSS 9.8) and affects internet-facing OFBiz deployments, which are commonly exposed for e-commerce and ERP functions.

9.8 CVSS 3.1 Critical EPSS 95% · top 0.1% CWE-94 · Code injection
9.8CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
13References
17 Jun 2026Last modified by NVD

Description

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network RCE with a CVSS of 9.8 and very high EPSS probability makes this an urgent patch-first issue for any exposed OFBiz instance.

What it is

Apache OFBiz before 18.12.10 ships a deprecated XML-RPC endpoint that allows code injection, resulting in remote code execution without authentication. The flaw is rated critical (CVSS 9.8) and affects internet-facing OFBiz deployments, which are commonly exposed for e-commerce and ERP functions.

Impact

An unauthenticated attacker can execute arbitrary code on the OFBiz server, leading to full compromise of the application and its data. This can enable data theft, persistence, and lateral movement into connected systems.

Attack surface

Reachable over the network via the XML-RPC interface; the CVSS vector shows no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N). Any OFBiz instance exposing the affected endpoint is directly attackable.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.95368, 99.864th percentile) and public exploit code exists (Packet Storm reference), indicating active exploitation is likely.

What to do

  • Upgrade Apache OFBiz to 18.12.10 or later immediately.
  • If upgrade is not possible, disable or block access to the XML-RPC endpoint at the network or reverse-proxy layer.
  • Restrict internet exposure of OFBiz management and RPC interfaces to trusted networks only.
  • Monitor vendor advisories and apply any follow-up patches for related OFBiz issues.
  • Review server logs for signs of compromise and rotate credentials if exploitation is suspected.

Detection

  • Inspect web server and OFBiz logs for POST requests to XML-RPC paths, especially from unexpected source IPs.
  • Alert on outbound network connections or process creation from the OFBiz service account that are not typical for the application.
  • Use the public Packet Storm exploit details to create signatures or YARA/Suricata rules for known payload patterns.
  • Monitor for unexpected file writes or new processes spawned by the Java process hosting OFBiz.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-49070 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-38856Apache OFBiz incorrect authorization allows unauthenticated code executionApache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if prec…KEVEPSS 99%analysed9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2023-49070), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.