Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
https://github.com/yuaneuro/ofbiz-poc
https://github.com/S0por/CVE-2021-26295-Apache-OFBiz-EXP
https://github.com/coolyin001/CVE-2021-26295--
https://github.com/TheTh1nk3r/exp_hub
https://github.com/dskho/CVE-2021-26295
https://github.com/r0ckysec/CVE-2021-26295
https://github.com/rakjong/CVE-2021-26295-Apache-OFBiz
http://packetstormsecurity.com/files/162104/Apache-OFBiz-SOAP-Java-Deserialization.html