CVE-2026-45434 — Apache OFBiz LoginWorker checkLogin 密码更改流程认证绕过远程代码执行
aretiq.ai | 研究 | CVE-2026-45434 | #rce | #authentication-bypass | #cve-2026-45434 | #apache-ofbiz | #groovy
摘要
CVE-2026-45434:Apache OFBiz 的 checkLogin 将 requirePasswordChange 流程误判为登录成功,攻击者可绕过锁定账户并经未沙箱化 ProgramExport 执行系统命令;24.09.06 已修复。
- CVE
- CVE-2026-45434
- 发布时间
- 收录时间
Skip to content