PT-2026-82306 · Antflow · Antflow

CVE-2026-75414

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AntFlow version 2.0.0
Description In the ActivitiTest.java file, the application allows users to execute JUEL (Java Unified Expression Language) expressions without proper filtering of user input. This lack of validation enables an attacker to perform command execution on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75414

Affected Products

Antflow