Remote Code Execution Vulnerability in Valtimo Automation Platform
CVE-2026-42555
What is CVE-2026-42555?
Valtimo, an open-source business process automation platform, contains a vulnerability that allows authenticated users with ADMIN roles to execute arbitrary code remotely. This occurs due to the evaluation of Spring Expression Language (SpEL) expressions from user-supplied input, leveraging StandardEvaluationContext without restrictions. Successful exploitation can lead to credential exfiltration and unauthorized access to sensitive information. This issue has been addressed in the following versions: com.ritense.valtimo:document 2.32.0, com.ritense.valtimo:case 13.23.0, and com.ritense.valtimo:contract 13.23.0. For more details, please refer to the advisory.
Affected Version(s)
case >= 13.0.0, < 13.23.0
contract >= 13.4.0, < 13.23.0
document >= 12.0.0, < 12.32.0
