← Back

Wire · technology

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Published

5 August 2026

Topic

technology

Sectors

Enterprise Software

Source

Read at helpnetsecurity.com

Verified

Fusion42 · 30 August 2026 · Fusion42 review

A critical pre-auth remote code execution vulnerability (CVE-2026-31986) affects Bonita BPM and Apache OFBiz enterprise Java platforms, allowing attackers to execute code unauthenticated via internal APIs and default keys. Both vendors have released timely patches following coordinated disclosure.

This Wire brief sits within Fusion42's coverage of Enterprise Software.

◆ The Wire takeaway

You must verify that your Java enterprise platforms aren’t running these versions with exposed internal APIs or default keys. Unpatched Bonita or OFBiz servers open your systems to untraceable remote attacks and demand immediate updates.

Coverage

1 source · 5 Aug 2026

Related on Wire

Topics

Enterprise Softwarerceenterprise-javavulnerabilitybonitaofbizsecurity-patch