Apache OFBiz IMPAUTH pre24.09.06
CVE-2026-31387 Published on May 19, 2026

Apache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account Impersonation
Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Vendor Advisory NVD

Weakness Type

What is an authentification Vulnerability?

When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.

CVE-2026-31387 has been classified to as an authentification vulnerability or weakness.


Products Associated with CVE-2026-31387

Want to know whenever a new CVE is published for Apache OFBiz? stack.watch will email you.

 

Affected Versions

Apache Software Foundation Apache OFBiz: