PT-2026-91743 · Activiti · Activiti

·

CVE-2026-91145

·

Published

2026-09-14

·

Updated

2026-09-15

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Activiti versions prior to 7.1.0.M7
Description Failure to validate hash-brace deferred expressions in process variables allows attackers to bypass expression filtering. By injecting expressions starting with #{, an attacker can store these expressions, which are subsequently evaluated within the full Spring context when a mail task utilizes variable-backed body fields. This mechanism enables unauthorized method invocation on application beans.
Recommendations Update to a version later than 7.1.0.M6.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91145

Affected Products

Activiti