Remote Code Execution Vulnerability in Valtimo Automation Platform
CVE-2026-42555

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-42555?

Valtimo, an open-source business process automation platform, contains a vulnerability that allows authenticated users with ADMIN roles to execute arbitrary code remotely. This occurs due to the evaluation of Spring Expression Language (SpEL) expressions from user-supplied input, leveraging StandardEvaluationContext without restrictions. Successful exploitation can lead to credential exfiltration and unauthorized access to sensitive information. This issue has been addressed in the following versions: com.ritense.valtimo:document 2.32.0, com.ritense.valtimo:case 13.23.0, and com.ritense.valtimo:contract 13.23.0. For more details, please refer to the advisory.

Affected Version(s)

case >= 13.0.0, < 13.23.0

contract >= 13.4.0, < 13.23.0

document >= 12.0.0, < 12.32.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.