Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
2026-08-05T20:51:42Z•6c5ce765021a5eba5b6c241b832ed2729cb50ae1529b0a977cfa374a43cce120
CVE-2026-31986AI-securityApache-OFBizBonita-BPMcybercrime-trendsenterprise-javapre-authenticationremote-code-executionunauthenticated-accessvulnerability-discoveryweb-exploitation
What happened
The feed reports a pre-authentication remote code execution vulnerability affecting enterprise Java servers, specifically Bonita and Apache OFBiz, exploitable through a single unauthenticated web request. The issue could enable attackers to execute code on exposed hosts supporting critical business workflows. It also covers AI-driven security products, automated vulnerability discovery, AI-agent abuse scenarios, and broader cybercrime trends, but provides no additional confirmed vulnerability identifiers beyond CVE-2026-31986.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 6c5ce765021a5eba5b6c241b832ed2729cb50ae1529b0a977cfa374a43cce120
- Enrichment time
- 2026-08-05T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.