Research Bonita BPM web-app Apache OFBiz Bonita rce
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
CVE Tools coverage
Researchers uncovered a critical pre-authentication remote code execution (RCE) vulnerability affecting enterprise Java platforms, including Bonita BPM and Apache OFBiz. The flaw, tracked as CVE-2026-31986, allows attackers to send unauthenticated HTTP requests that bypass multiple security layers and execute arbitrary code on the server. This affects systems used by banks, insurers, and governments for workflow automation. Attackers exploit misconfigured API routing, insecure deserialization in XStream, and predictable signing keys to gain full control without authentication. Both vendors have issued patches within the standard disclosure timeline. Users should upgrade immediately to avoid potential exploitation.