Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
ResearchBonita BPMApache OFBizOur summary
Researchers uncovered a critical pre-authentication remote code execution (RCE) vulnerability affecting enterprise Java platforms, including Bonita BPM and Apache OFBiz. The flaw, tracked as CVE-2026-31986, allows attackers to send unauthenticated HTTP requests that bypass multiple security layers and execute arbitrary code on the server. This affects systems used by banks, insurers, and governments for workflow automation. Attackers exploit misconfigured API routing, insecure deserialization in XStream, and predictable signing keys to gain full control without authentication. Both vendors have issued patches within the standard disclosure timeline. Users should upgrade immediately to avoid potential exploitation.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.