Wire · technology
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 30 August 2026 · Fusion42 review
A critical pre-auth remote code execution vulnerability (CVE-2026-31986) affects Bonita BPM and Apache OFBiz enterprise Java platforms, allowing attackers to execute code unauthenticated via internal APIs and default keys. Both vendors have released timely patches following coordinated disclosure.
This Wire brief sits within Fusion42's coverage of Enterprise Software.
◆ ◆ The Wire takeaway
You must verify that your Java enterprise platforms aren’t running these versions with exposed internal APIs or default keys. Unpatched Bonita or OFBiz servers open your systems to untraceable remote attacks and demand immediate updates.
◆ Coverage
1 source · 5 Aug 2026
◆ Related on Wire
◆ Topics