CVE-2026-91145
Awaiting Analysis Awaiting Analysis - Queue

Expression Injection in Activiti Workflow Engine

Vulnerability report for CVE-2026-91145, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-24

Assigner: VulnCheck

Description

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, enabling method invocation on application beans.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-24
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
activiti activiti to 7.1.0.M6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-917 The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Activiti through version 7.1.0.M6 does not properly validate hash-brace deferred expressions in process variables. Attackers can inject expressions starting with #{ that bypass filtering. These expressions are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, allowing method invocation on application beans.

Detection Guidance

To detect this vulnerability, inspect Activiti deployments for process definitions containing mail tasks with variable-backed body fields. Check for deferred expressions starting with #{ in stored process variables. Review logs for unexpected method invocations or bean access in Spring context.

Impact Analysis

An attacker could exploit this to execute arbitrary methods on application beans, potentially leading to unauthorized data access, code execution, or other malicious actions depending on the application's configuration and exposed beans.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected versions may face compliance violations, data breach notifications, and potential fines if exploited.

Mitigation Strategies

Upgrade Activiti to a version beyond 7.1.0.M6 where the hash-brace deferred expression validation issue is fixed. Review mail task configurations to ensure variable-backed body fields are not used or are properly sanitized.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91145. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart