Sensitive Data Exposure in Valtimo Business Process Automation Platform
CVE-2026-34164
4.9MEDIUM
What is CVE-2026-34164?
The Valtimo Business Process Automation Platform has a vulnerability that causes the InboxHandlingService to log sensitive inbox messages, including personal data such as PII and citizen identifiers. This logging occurs at the INFO level, making it accessible to any user with admin access or those who can view application logs. To mitigate this risk, it is recommended to upgrade to version 13.22.0 or, as a temporary measure, restrict access to logs and set the logging level for com.ritense.inbox to WARN or higher.
Affected Version(s)
valtimo >= 13.0.0.RELEASE, < 13.22.0.RELEASE
