Apache OFBiz Expression Language Injection Vulnerability

Vulnerability

A vulnerability allowing improper neutralization of special elements in an Expression Language statement has been identified in Apache OFBiz versions prior to 24.09.06. This 'Expression Language Injection' issue could potentially be exploited to manipulate expression evaluation in an unintended manner.

Impact

Exploitation of this vulnerability could lead to Server-Side Template Injection (SSTI) in FreeMarker, allowing attackers to execute arbitrary code on the server.

Remediation

Users are advised to upgrade to Apache OFBiz version 24.09.06 or later, which addresses this vulnerability.

Added: May 19, 2026, 10:29 AM
Updated: May 19, 2026, 10:29 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
7.5
exploitability
7.4
remediation
3.1
relevance
8.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.