Junglewise Threat Intelligence

CVE-2026-42555: Ritense Valtimo SpEL injection in DocumentMigrationService and Condition

CVE-2026-42555 · Severity: critical · CVSS 9.1 · Published 2026-05-14

Vendors: Maven.

Executive brief

Valtimo is an open-source business process automation platform. A security vulnerability allows users with administrative privileges to execute unauthorized commands on the underlying server and steal sensitive configuration data, such as database passwords and API keys. This could lead to a complete takeover of the platform and exposure of all managed business data.

Technical details

The vulnerability exists in multiple components, including DocumentMigrationService and the Condition framework, which evaluate user-supplied Spring Expression Language (SpEL) expressions using an unrestricted StandardEvaluationContext. By submitting malicious expressions in REST API fields (like 'source' or 'target' in document migration) or JSON configurations for widgets, an attacker with ADMIN privileges can invoke arbitrary Java methods. This allows for OS command execution via java.lang.Runtime, environment variable exfiltration, and arbitrary class loading. The issue is resolved by migrating to SimpleEvaluationContext, which restricts access to dangerous Java types.

Affected products

  • Ritense valtimo-platform/valtimo >= 12.0.0, < 12.32.0; >= 13.0.0, < 13.23.0

Timeline

  • 2026-05-01: disclosed
  • 2026-05-06: advisory
  • 2026-05-14: patched: NVD publication and patch confirmation

References

Related threats