Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apache OFBiz Forced Browsing Vulnerability

Vulnerability

A forced browsing vulnerability has been identified in Apache OFBiz versions prior to 18.12.16. This vulnerability allows unauthorized access to rendered views by exploiting confused controller-view authorization logic. Users are advised to upgrade to version 18.12.16, which addresses this issue by introducing a new permission check for view-maps and changing the default settings for request-maps.

Impact

Exploitation of this vulnerability could lead to unauthorized access to views that should be restricted, allowing users to view or interact with content or functionality they are not permitted to access.

Remediation

Users can upgrade to Apache OFBiz version 18.12.16 to address this vulnerability. Instructions for downloading this version are available on the Apache OFBiz download page.

Added: Mar 16, 2026, 8:42 PM
Updated: Mar 16, 2026, 8:42 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
8.3
remediation
7.7
relevance
0.0
threat
10.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.