CVE Tools
Back to feed
Research Bonita BPM web-app Apache OFBiz Bonita rce

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Help Net Security·By Mirko Zorz··5 min read
CVE Tools coverage

Researchers uncovered a critical pre-authentication remote code execution (RCE) vulnerability affecting enterprise Java platforms, including Bonita BPM and Apache OFBiz. The flaw, tracked as CVE-2026-31986, allows attackers to send unauthenticated HTTP requests that bypass multiple security layers and execute arbitrary code on the server. This affects systems used by banks, insurers, and governments for workflow automation. Attackers exploit misconfigured API routing, insecure deserialization in XStream, and predictable signing keys to gain full control without authentication. Both vendors have issued patches within the standard disclosure timeline. Users should upgrade immediately to avoid potential exploitation.