{"id":"CVE-2023-51467","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-51467","summary":"The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code\n\n","details":"The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code\n\n","published":"2023-12-26T15:15:08.853","modified":"2026-06-17T06:41:00.937","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.96001,"percentile":0.9987,"asOf":"2026-08-25"},"cisaKev":null,"exploitsKnown":12,"affectedPackages":[],"fix":null,"references":[{"type":"FIX","url":"https://issues.apache.org/jira/browse/OFBIZ-12873"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/9tmf9qyyhgh6m052rhz7lg9vxn390bdv"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/oj2s6objhdq72t6g29omqpcbd1wlp48o"},{"type":"WEB","url":"https://ofbiz.apache.org/download.html"},{"type":"WEB","url":"https://ofbiz.apache.org/release-notes-18.12.11.html"},{"type":"WEB","url":"https://ofbiz.apache.org/security.html"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/12/26/3"},{"type":"FIX","url":"https://issues.apache.org/jira/browse/OFBIZ-12873"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/9tmf9qyyhgh6m052rhz7lg9vxn390bdv"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/oj2s6objhdq72t6g29omqpcbd1wlp48o"},{"type":"WEB","url":"https://ofbiz.apache.org/download.html"},{"type":"WEB","url":"https://ofbiz.apache.org/release-notes-18.12.11.html"},{"type":"WEB","url":"https://ofbiz.apache.org/security.html"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2023/12/26/3"},{"type":"WEB","url":"https://www.vicarius.io/vsociety/posts/apache-ofbiz-authentication-bypass-vulnerability-cve-2023-49070-and-cve-2023-51467"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T06:41:00.937"}}