/00 — boot sequence

Hello.

Article

Enterprise Java Pre-Auth RCE: CVE-2026-31986 in OFBiz

August 10, 2026•6 min read
CVE Java RCE Apache OFBiz Bonita BPM Enterprise Security

At Black Hat USA 2026 this week, researchers from Novee presented a briefing on enterprise Java pre-auth RCE that covers two widely deployed platforms: Apache OFBiz and Bonita BPM. An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. For OFBiz, two unauthenticated GET requests reach code execution when single sign-on is enabled. The OFBiz chain carries CVE-2026-31986, rated critical. Both vendors have already shipped fixes.

Bonita BPM handles loan approvals, insurance claims, and employee onboarding for banks, insurers, and government agencies. Apache OFBiz runs e-commerce, accounting, and CRM for companies that want an open source ERP. Neither platform expects a complete stranger to reach its execution paths.

The Audit: Twelve Flaws in Four Platforms

The Novee team audited four enterprise Java platforms and found twelve vulnerabilities, including a sandbox escape and four flaws that work before any login. They walked through two of the chains in detail, one in Bonita and one in OFBiz. Both follow the same pattern: routing reached a surface that trusted its callers, and an execution sink turned that reach into running code.

The Bonita Chain: One Web Address Walks Past Three Guards

Bonita BPM 10.4.3 runs a public API surface and an internal API surface. The public surface wants a session and a CSRF token. The internal surface takes basic auth and feeds whatever it receives to XStream, a library that turns XML into live Java objects. Three separate checks guard the boundary between the two surfaces, and a single web address defeats all of them at once.

The first check reads a path one way while Tomcat's dispatcher reads it another. A path segment written as ..; passes the security filter as an ordinary name. Tomcat strips the semicolon, treats the remainder as a step up the directory tree, and routes the request onto the internal surface.

The second check runs a match that fires on any substring. A fabricated app name in the path satisfies the auth filter, and the same substring satisfies the CSRF filter. Both filters stop reading at the substring they matched.

The remaining check protects direct requests and passes forwarded ones. Bonita declares that protection for a single request type and omits the rest, so a request arriving by internal forward passes untouched.

Chained together, the gaps fold the login wall into a single POST request. The attacker stands inside the internal API, unauthenticated. From there, XStream accepts any type. Attacker XML rebuilds a gadget chain from Commons Collections classes, routes it through a memory shortcut that skips the usual safety checks, and reaches a Groovy call that runs a command. The whole sequence executes inside one XStream call before the request finishes.

The OFBiz Chain: One Key Unlocks Everything

Apache OFBiz 24.09.05 signs its single sign-on tokens with a key stored in a config file. That key ships in the public source repository. Every install that keeps the default signs tokens with a secret anyone can read.

Sign a token with that key and OFBiz trusts the claims inside it. Set the user to admin and an admin session appears. The attacker holds admin rights with a forged token.

The same key signs the widget engine's callback tokens. A token carries a field naming a screen area to render. OFBiz reads the field off the token and pipes it into a template expander that evaluates Groovy. An accessibility preference decides whether that evaluation runs, and an admin can flip it. The forged admin flips it, then sends a token carrying a Groovy command in place of the screen name.

A denylist tries to block script injection. It matches lowercase text and known prefixes. A capital P on ProcessBuilder slips past it. An auto-imported class needs no prefix and slips past it too.

The result is CVE-2026-31986, rated critical: two unauthenticated GET requests reach code execution on any OFBiz install with single sign-on turned on.

Why These Chains Are Hard to Spot

Each chain is built from parts that look harmless on their own. A stray URL segment. A match set to the wrong mode. A missing line in a config file. A default key. A regex with no case flag. A signature scanner has nothing to match. A generic model reads the code and flags a possible deserialization, but proof that the sink is reachable stays absent. The exploit lives in how the pieces connect.

Mitigation & Patching

The good news is that fixes exist. OFBiz has released new versions that address these vulnerabilities, and Bonita has released a new version following the disclosure. Novee worked with both projects before publication, and both vendors completed fixes within the standard 90-day disclosure timeline. OFBiz in particular kept the researchers updated throughout remediation.

  • Upgrade Apache OFBiz to the patched release immediately, especially if single sign-on is enabled.
  • Upgrade Bonita BPM to the patched release.
  • If you cannot upgrade right away, disable OFBiz single sign-on and treat the default signing key as compromised: rotate it to a per-install secret.
  • Harden internal routing as though it sits on the internet. The Bonita internal API should not be reachable by request forwarding tricks.
  • Remove unsafe execution primitives. A rendering toggle should never gate a call to eval, and XML deserialization of untrusted input should not exist.
  • Run an audit pass on path normalization, filter substring matching, and forwarded-request handling in any Java web app you operate.

Detection

Signature-based scanners will struggle with these chains. Do not rely on them alone.

  • Watch for SSO sessions with privileged claims, for example an admin claim, appearing from unfamiliar IPs.
  • Look for requests to internal API paths, especially ones carrying odd path segments such as ..;.
  • Log XStream deserialization activity and Groovy evaluation errors where you can.
  • Alert on patterns of two rapid GET requests against OFBiz SSO endpoints.

Frequently Asked Questions

Is CVE-2026-31986 patched? Yes. Apache OFBiz released new versions addressing these vulnerabilities, and Bonita also released a new version. Both happened inside the standard 90-day disclosure window.

Do these attacks require authentication? No. The Bonita reach-in is a single unauthenticated request. The OFBiz chain needs two unauthenticated GET requests and single sign-on enabled.

Which versions are affected? Apache OFBiz 24.09.05 (and any install keeping the default SSO signing key) and Bonita BPM 10.4.3, with earlier versions likely affected too.

Is this research AI-assisted? Novee builds an offensive AI system. Its founder told Help Net Security the majority of the research was performed by humans, with targeted assistance from the Novee agent during the work.

What about the other two platforms audited? They stay unnamed. The researchers said both are large enterprise platforms with lower impact than Bonita and OFBiz, and they have not received recent updates from either vendor.

Key Takeaways

  • CVE-2026-31986 is a critical pre-auth RCE in Apache OFBiz reached through a forged SSO token signed with the default key.
  • Bonita BPM 10.4.3 falls to an unauthenticated chain that bypasses three boundary checks and lands in an XStream gadget chain.
  • Both vendors patched inside the 90-day disclosure window, so the response is an upgrade, not a wait.
  • The pattern that matters: routing checks that trust each other, unsafe XML deserialization, and signing keys shipped in public repos.

Sources: Help Net Security, GBHackers, Novee

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links