CVE-2021-26295

CRITICAL EXPLOITED NUCLEI

Apache OFBiz SOAP Java Deserialization

Title source: metasploit

Description

Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.

Exploits (7)

nomisec WORKING POC 23 stars
by yumusb · remote-auth
https://github.com/yumusb/CVE-2021-26295
nomisec WORKING POC 6 stars
by yuaneuro · poc
https://github.com/yuaneuro/ofbiz-poc
nomisec WORKING POC 4 stars
by rakjong · remote-auth
https://github.com/rakjong/CVE-2021-26295-Apache-OFBiz
nomisec SUSPICIOUS
by coolyin001 · poc
https://github.com/coolyin001/CVE-2021-26295--
nomisec WORKING POC
by dskho · poc
https://github.com/dskho/CVE-2021-26295
metasploit WORKING POC EXCELLENT
by yumusb, Spencer McIntyre, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/apache_ofbiz_deserialization_soap.rb

Nuclei Templates (1)

Apache OFBiz <17.12.06 - Arbitrary Code Execution
CRITICALVERIFIEDby madrobot
Shodan: OFBiz.Visitor= || http.html:"ofbiz" || ofbiz.visitor=
FOFA: body="ofbiz" || app="apache_ofbiz"

References (13)

Scores

CVSS v3 9.8
EPSS 0.9424
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-12-05
CWE
CWE-502
Status published
Products (1)
apache/ofbiz < 17.12.06
Published Mar 22, 2021
Tracked Since Feb 18, 2026