Apache OFBiz Improper Authorization Vulnerability in Webtools Allowing Low-Privileged Users to Submit System Jobs

Vulnerability

A moderate improper authorization vulnerability has been identified in Apache OFBiz Webtools, affecting versions prior to 24.09.06. This vulnerability allows low-privileged users to submit system jobs, which could potentially be misused to execute unauthorized tasks within the application.

Impact

Exploitation of this vulnerability could lead to unauthorized submission of system jobs by low-privileged users, allowing them to execute tasks that could disrupt normal operations or access sensitive information.

Remediation

Users are advised to upgrade to Apache OFBiz version 24.09.06 or later, which addresses this vulnerability.

Added: May 19, 2026, 10:24 AM
Updated: May 19, 2026, 10:24 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
3.1
relevance
8.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.