CVE-2026-31380: Apache OFBiz

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Affected products

  • Apache OFBiz: before 24.09.06 (fixed in 24.09.06)

Published 2026-05-19. Last modified 2026-06-17.