Liferay Portal contains a flaw that is triggered when an error occurs during the handling of organization permissions. Due to improper access controls, a remote attacker may be able to change the omni-admin password.
The vendor has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section. There are no known workarounds or upgrades to correct this issue.