Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some preconditions are met (such as when the screen definitions don't explicitly check user's permissions because they rely on the configuration of their endpoints).
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38856
https://lists.apache.org/thread/olxxjk6b13sl3wh9cmp0k2dscvp24l7w
https://github.com/chengbochuan3/CVE-Web-Framework
https://github.com/ykrishhh/cve-pocs
https://github.com/lwd3c/CVE-2026-47342
https://github.com/Hex00-0x4/CVE-2024-38856-Apache-OFBiz
https://github.com/guinea-offensive-security/Ofbiz-RCE
https://github.com/ismailmazumder/SL7CVELabsBuilder
https://github.com/securelayer7/SL7CVELabsBuilder
https://github.com/AlissonFaoli/Apache-OFBiz-Exploit
https://github.com/FakesiteSecurity/CVE-2024-38856_Scen
https://github.com/XiaomingX/cve-2024-38856-poc
https://github.com/BBD-YZZ/CVE-2024-38856-RCE
https://github.com/emanueldosreis/CVE-2024-38856
https://github.com/jocker2410/CVE-2024-38856
https://github.com/0x20c/CVE-2024-38856-EXP
https://github.com/Praison001/CVE-2024-38856-ApacheOfBiz
https://github.com/ThatNotEasy/CVE-2024-38856
https://github.com/codeb0ss/CVE-2024-38856-PoC
https://github.com/securelayer7/CVE-2024-38856_Scanner
https://github.com/Disseminator/Poc_CVEs
https://ofbiz.apache.org/security.html
https://ofbiz.apache.org/download.html
Published: 2024-08-05
Updated: 2025-10-23
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99427
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored