← Vulnerability feed

Vulnerability record · CVE-2024-38856 · published 5 August 2024

CVE-2024-38856: Apache OFBiz incorrect authorization allows unauthenticated code execution

Apache · Ofbiz

Apache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if preconditions are met, such as screen definitions relying on endpoint configuration instead of explicit permission checks. It matters because the flaw is remotely reachable without credentials and is listed in CISA KEV, so it is being exploited in the wild.

9.8 CVSS 3.1 Critical CISA KEV since 27 Aug 2024 EPSS 99% · top 0.1% CWE-863 · Incorrect authorization
9.8CVSS 3.1 base score
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network exploitation, KEV listing and near-maximum EPSS probability make this an urgent patch-first issue.

What it is

Apache OFBiz through 18.12.14 has an incorrect authorization flaw (CWE-863) where unauthenticated endpoints can execute screen rendering code if preconditions are met, such as screen definitions relying on endpoint configuration instead of explicit permission checks. It matters because the flaw is remotely reachable without credentials and is listed in CISA KEV, so it is being exploited in the wild.

Impact

An unauthenticated attacker can execute screen rendering code on the server, which can lead to full compromise of confidentiality, integrity and availability. CVSS 3.1 scores it 9.8 with high impact across all three categories.

Attack surface

Reachable over the network via unauthenticated endpoints; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. Exploitation depends on preconditions such as screen definitions that do not explicitly check permissions.

Exploitation

CISA added it to KEV on 2024-08-27 with a 2024-09-17 remediation due date, and EPSS gives a 30-day probability of 0.99427 (99.94th percentile). No ransomware campaign use is documented in the record.

What to do

  • Upgrade Apache OFBiz to 18.12.15 or later, which the vendor states fixes the issue.
  • If immediate upgrade is not possible, restrict network access to OFBiz endpoints to trusted sources and follow vendor mitigation guidance.
  • Review screen definitions and endpoint configurations for missing explicit permission checks.
  • Monitor the Apache OFBiz security page and mailing list for further vendor guidance.
  • Treat internet-exposed OFBiz instances as compromised until triaged, given KEV listing and active exploitation.

Detection

  • Hunt for unexpected requests to unauthenticated OFBiz endpoints, especially those that trigger screen rendering, in web access logs.
  • Look for anomalous process execution or child processes spawned by the OFBiz Java process.
  • Alert on outbound connections from OFBiz hosts to unfamiliar destinations, which may indicate post-exploitation activity.
  • Correlate OFBiz access logs with file writes or new files in web-accessible directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-38856 to the Known Exploited Vulnerabilities catalog on 27 August 2024 as "Apache OFBiz Incorrect Authorization Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 17 September 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-38856 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-32113Apache OFBiz path traversal allows unauthenticated remote compromiseApache OFBiz before 18.12.13 fails to properly restrict pathnames to a restricted directory, allowing path traversal (CWE-22). Because the flaw is re…KEVEPSS 100%analysed7.5CVE-2024-45195Apache OFBiz forced browsing exposes restricted endpointsApache OFBiz before 18.12.16 is affected by a direct request (forced browsing) flaw, CWE-425, that lets a remote unauthenticated client reach functio…KEVEPSS 100%analysed10.0CVE-2013-2250Apache ofbiz improper input validation vulnerabilityApache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute ar…EPSS 12%10.0CVE-2012-3506Apache ofbiz vulnerabilityUnspecified vulnerability in the Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.03 has unknown impact and attack vectors.EPSS 7.5%9.8CVE-2026-45434Apache ofbiz improper authentication vulnerabilityImproper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz…EPSS 1.3%9.8CVE-2025-54466Apache ofbiz code injection vulnerabilityImproper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Ap…EPSS 17%9.8CVE-2024-47208Apache ofbiz code injection vulnerabilityServer-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apach…EPSS 1.6%9.8CVE-2024-45507Apache OFBiz SSRF and code injection before 18.12.16Apache OFBiz before 18.12.16 is affected by a server-side request forgery flaw combined with improper control of code generation (code injection). Th…EPSS 93%analysed

Source: NIST National Vulnerability Database (record CVE-2024-38856), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.