# CVE-2026-11561

## Summary

- **CVE ID:** CVE-2026-11561
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-917
- **Published:** Jun 11, 2026
- **Last Modified:** Jun 12, 2026

## Description

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection.

This issue affects Apinizer: from 2026.04.0 before 2026.04.6.

## Affected Products

- Soagen Informatics Technologies Software and Consulting Inc. — Apinizer (2026.04.0)

## References

- [CNA](https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0365)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.45%
- **EPSS Percentile:** 37.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._