CVE-2023-49070: Apache OFBiz

Critical severity, CVSS 9.8. EPSS: 95.4% chance of exploitation in the next 30 days.

Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

Affected products

  • Apache OFBiz: before 18.12.10 (fixed in 18.12.10)

Published 2023-12-05. Last modified 2026-06-17.