CVE-2026-47342
HIGHApache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-47342. PoCs published by lwd3c.
AI-analyzed exploit summary This repository contains a functional exploit chain for CVE-2026-47342, targeting Apache OFBiz. The PoC demonstrates privilege escalation from ORDERPURCH to FULLADMIN and achieves remote code execution via Groovy injection in the scheduleServiceSync endpoint.
Description
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.
Exploits (1)
This repository contains a functional exploit chain for CVE-2026-47342, targeting Apache OFBiz. The PoC demonstrates privilege escalation from ORDERPURCH to FULLADMIN and achieves remote code execution via Groovy injection in the scheduleServiceSync endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H