Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, enabling method invocation on application beans.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, enabling method invocation on application beans. | |
| Title | Activiti through 7.1.0.M6 Expression Injection via Mail Task | |
| Weaknesses | CWE-917 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T21:45:45.317Z
Reserved: 2026-09-14T20:35:44.937Z
Link: CVE-2026-91145
No data.
Status : Received
Published: 2026-09-14T22:16:59.217
Modified: 2026-09-14T22:16:59.217
Link: CVE-2026-91145
No data.
OpenCVE Enrichment
No data.
Weaknesses