CVE-2021-26295
RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI
- Published
- Mar 22, 2021
- Updated
- Feb 13, 2025
- Assigning CNA
- apache
- Evidence observed
- Aug 24, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to successfully take over Apache OFBiz.
Sources
7- CVE-2021-26295--Exploit
CVE-2021-26295-POC 利用DNSlog进行CVE-2021-26295的漏洞验证。 使用 poc:将目标放于target.txt后运行python poc.py即可。(Jdk环境需<12,否则ysoserial无法正常生成有效载荷) exp:python exp.py https://baidu.com然后进入命令执行界面(无回显)
- ofbiz-pocExploit
CVE-2020-9496 and CVE-2021-26295 batch verification PoC and exploit using dnslog
- CVE-2021-26295Exploit
Proof-of-concept exploit for CVE-2021-26295 (Apache OFBiz RCE) using DNSlog for out-of-band vulnerability verification. Includes command execution interface and ysoserial payload generation.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.