Information Exposure in Valtimo Business Process Automation Platform by Valtimo
CVE-2026-44516

7.6HIGH

Key Information:

Vendor
CVE Published:
14 May 2026

What is CVE-2026-44516?

The Valtimo business process automation platform contains a vulnerability where the LoggingRestClientCustomizer in the web module logs sensitive information from all outgoing HTTP requests and responses. This includes the full request body, response body, and response headers which may inadvertently expose confidential data. In cases of error responses, this information is logged at the ERROR level, regardless of the application's debug-level settings. This raises significant security and privacy concerns, especially for applications handling sensitive data. The vulnerability affects versions ranging from 12.4.0 to 12.33.0 and 13.26.0, and it has been addressed in the latest releases.

Affected Version(s)

valtimo >= 12.4.0, < 12.33.0 < 12.4.0, 12.33.0

valtimo >= 13.0.0, < 13.26.0 < 13.0.0, 13.26.0

web >= 12.4.0, < 12.33.0 < 12.4.0, 12.33.0

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.