Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, enabling method invocation on application beans. | |
| Title | Activiti through 7.1.0.M6 Expression Injection via Mail Task | |
| Weaknesses | CWE-917 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T21:45:45.317Z
Reserved: 2026-09-14T20:35:44.937Z
Link: CVE-2026-91145
No data.
Status : Received
Published: 2026-09-14T22:16:59.217
Modified: 2026-09-14T22:16:59.217
Link: CVE-2026-91145
No data.
OpenCVE Enrichment
No data.