CVE-2026-46586
Improper Control of Generation of Code (‘Code Injection’), Improper Neutralization of Directives in Dynamically Evaluated Code (‘Eval Injection’) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
More information : https://lists.apache.org/thread/7mgjl81nrpxqtfcg6h5qtrx7wztbl4js
