CVE-2026-91145
Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, enabling method invocation on application beans.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.24%
- CWE
- CWE-917
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- Activiti Activiti
Weakness type
Related vulnerabilities
- CVE-2021-45046 — Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
- CVE-2025-41243 — Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
- CVE-2025-3322 — Improper Neutralization of Special Elements in OnlineSuite
- CVE-2023-41331 — SOFARPC Remote Command Execution (RCE) Vulnerability
- CVE-2023-51593 — Voltronic Power ViewPower Pro Expression Language Injection Remote Code Execution Vulnerability
- CVE-2022-23463 — SpEL Injection in Nepxion Discovery
- CVE-2024-51466 — IBM Cognos Analytics expression language injection
- CVE-2023-42658 — InSpec Archive Command Vulnerable to Maliciously Crafted Profile