CVE-2026-31986 is a critical vulnerability in Apache OFBiz affecting versions before 24.09.06. The root cause is the use of a hard-coded or default cryptographic signing key for JWT-based single sign-on and related token validation. On installations that retain the default key, an unauthenticated attacker can forge trusted tokens and impersonate an administrator. Research describing the issue indicates that the forged administrator context can be used to enable a required preference, after which a second forged token abuses the widget rendering flow by supplying attacker-controlled input to a template expansion and Groovy evaluation path. The vulnerable logic relies on signed data being trusted based primarily on signature validation, while the same shared key is accepted across trust boundaries and token purposes. In affected configurations, this enables a pre-authentication remote code execution chain using only crafted requests.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical pre-authentication remote code execution chain in Apache OFBiz that abuses default JWT signing keys, forged tokens, preference manipulation, and Groovy expression evaluation to achieve code execution on SSO-enabled systems.
A critical unauthenticated remote code execution vulnerability chain in Apache OFBiz that abuses a publicly known default SSO signing key to forge admin tokens and then inject Groovy code via the widget engine callback token handling.
A hard-coded cryptographic key vulnerability in Apache OFBiz affecting versions before 24.09.06.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.