As cited
Copy frozen at (site build).
vulnerabilities
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
Security researchers discovered a pre-authentication remote code execution vulnerability in Bonita BPM and OFBiz that allows unauthenticated attackers to reach internal APIs and execute code on affected servers. Bonita is widely deployed in financial services, insurance, and government agencies for workflow automation. The vulnerability was presented at Black Hat USA 2026 by researchers at Novee.
Why it matters: Organizations running Bonita or OFBiz in production face immediate risk of complete compromise without authentication or network access controls, and should assess exposure and apply patches urgently.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
Security researchers discovered a pre-authentication remote code execution vulnerability in Bonita BPM and OFBiz that allows unauthenticated attackers to reach internal APIs and execute code on affected servers. Bonita is widely deployed in financial services, insurance, and government agencies for workflow automation. The vulnerability was presented at Black Hat USA 2026 by researchers at Novee.
Why it matters: Organizations running Bonita or OFBiz in production face immediate risk of complete compromise without authentication or network access controls, and should assess exposure and apply patches urgently.
- Source published
- First seen by Cybersecurity Tracker