CVE-2026-41919
Critical
Published: 19 May 2026
Published
19 May 2026
Modified
19 May 2026
KEV Added
—
Patch
—
CVSS Score
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.0003
8.3th percentile
Risk Priority
18
60% EPSS · 20% KEV · 20% CVSS
Summary
CVE-2026-41919 is a critical-severity LDAP Injection (CWE-90) vulnerability in Apache Ofbiz. Its CVSS base score is 9.1 (Critical).
Operationally, ranked at the 8.3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
NVD Description
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)
Affected Products
apache
ofbiz
≤ 24.09.06