OpsBuzz

Alert

Apache OFBiz Forced Browsing Vulnerability

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.Vendor: ApacheProduct: OFBizDue date: 202

Security · HIGH
Source: CISA Known Exploited VulnerabilitiesMay 2, 2026, 4:51 PMSecurityhigh

Full content

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

Vendor: Apache

Product: OFBiz

Due date: 2025-02-25

Known ransomware use: Unknown

Why it matters

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Related alerts