CVE-2026-29207
MEDIUM EPSS 41.4%
Published May 19, 20261mo ago · Modified Jun 17, 20262w ago
6.5 CVSS 3.1
Published May 19, 2026 1mo ago
Last Modified Jun 17, 2026 2w ago
Description
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. Please note that in the updated version, "Data Resource" records with dataTemplateTypeId = "FTL" are no longer supported. Additionally, in the updated version, the "Ecommerce Customer" security group no longer includes content management grants. Users are advised to remove these permissions from any production site as well.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
41.4% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-1336
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| apache | ofbiz | * | <24.09.06 |
References 2
- openwall.com http://www.openwall.com/lists/oss-security/2026/05/19/14
- lists.apache.org https://lists.apache.org/thread/3rcrp8bh3x6ovrj5xnc0fm1f0nrn52r0
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.