CVE-2023-49070: Apache OFBiz
Critical severity, CVSS 9.8. EPSS: 95.4% chance of exploitation in the next 30 days.
Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10. Users are recommended to upgrade to version 18.12.10
Affected products
- Apache OFBiz: before 18.12.10 (fixed in 18.12.10)
Published 2023-12-05. Last modified 2026-06-17.