Expression Injection Vulnerability in Activiti Product by Activiti
CVE-2026-91145
7.1HIGH
What is CVE-2026-91145?
Activiti versions prior to 7.1.0.M6 exhibit a vulnerability where hash-brace deferred expressions in process variables are not adequately validated. This flaw allows an attacker to inject expressions that start with '#{', which are subsequently stored and evaluated within the full Spring context during the execution of mail tasks. As a result, malicious users can invoke methods on application beans, potentially compromising the integrity and security of the application. Addressing this vulnerability is crucial for maintaining secure operations within affected deployments.
Affected Version(s)
Activiti 0 <= 7.1.0.M6
