CVE Tools

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Help Net SecurityBy Mirko Zorz

ResearchBonita BPMApache OFBiz

Our summary

Researchers uncovered a critical pre-authentication remote code execution (RCE) vulnerability affecting enterprise Java platforms, including Bonita BPM and Apache OFBiz. The flaw, tracked as CVE-2026-31986, allows attackers to send unauthenticated HTTP requests that bypass multiple security layers and execute arbitrary code on the server. This affects systems used by banks, insurers, and governments for workflow automation. Attackers exploit misconfigured API routing, insecure deserialization in XStream, and predictable signing keys to gain full control without authentication. Both vendors have issued patches within the standard disclosure timeline. Users should upgrade immediately to avoid potential exploitation.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store