Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-45434 — Apache OFBiz LoginWorker checkLogin Password-Change Flow Authentication Bypass RCE

Summary

CVE-2026-45434: OFBiz's checkLogin misreads the requirePasswordChange flow as success, letting attackers bypass locked accounts and reach unsandboxed ProgramExport for OS command execution.
CVE
CVE-2026-45434
Published
Collected

original ↗