Researchers from Novee disclosed 12 vulnerabilities across four enterprise Java platforms, highlighting two pre-authentication remote code execution chains that affected Bonita BPM 10.4.3 and Apache OFBiz 24.09.05. The findings were presented at Black Hat USA 2026, with Bonita’s chain showing that a single unauthenticated POST request could bypass routing, authentication, and CSRF protections to reach an internal API that deserialized attacker-controlled XML through XStream, resulting in code execution. Novee said the broader audit also uncovered four pre-login flaws and a sandbox escape, but identified Bonita and OFBiz as the most severe cases.
In Apache OFBiz, researchers found that a default signing key exposed in the public source repository allowed attackers to forge JWT-based SSO tokens, impersonate an administrator, and then abuse callback token handling plus Groovy expression evaluation in the widget engine to achieve unauthenticated RCE. The issue, tracked as CVE-2026-31986 and rated Critical, reportedly required SSO to be enabled and could be triggered with only two GET requests. Both vendors released fixes within a standard 90-day disclosure window, while researchers urged organizations to apply updates, replace shared signing keys, normalize paths in authentication and CSRF filters, protect all dispatcher paths, and restrict deserialization and template evaluation features.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
At Black Hat USA 2026, Novee researchers publicly presented findings on 12 vulnerabilities across enterprise Java platforms, highlighting the most serious pre-authentication RCE chains in Bonita BPM and Apache OFBiz. The presentation detailed how Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 could be exploited before authentication.
Both Bonita and Apache OFBiz released fixes for the reported issues during the 90-day disclosure period before the research was made public. The fixes addressed the vulnerability chains disclosed by Novee.
The Apache OFBiz pre-authentication RCE chain affecting version 24.09.05 was assigned CVE-2026-31986 and rated Critical. The chain relied on a default signing key that enabled forged tokens and abuse of Groovy evaluation in widget rendering.
Novee reported 12 vulnerabilities across four enterprise Java platforms to the affected projects before publication under a coordinated disclosure process. The sources state Bonita and Apache OFBiz released fixes within a standard 90-day disclosure window.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.