Junglewise Threat Intelligence

CVE-2026-8759: xiandafu Beetl Expression Language injection in SpELFunction

CVE-2026-8759 · Severity: high · CVSS 7.3 · Published 2026-05-17

Vendors: Maven.

Executive brief

Beetl is a high-performance Java template engine used to generate dynamic web pages and documents. A security vulnerability exists in its Spring integration component that allows attackers to inject malicious code through expression language statements. If exploited, this could allow an attacker to execute unauthorized commands or access sensitive data on the server, potentially leading to a full system compromise.

Technical details

A vulnerability classified as CWE-917 (Expression Language Injection) exists in the SpELFunction extension of Beetl up to version 3.20.2.RELEASE. The issue is located in the `SpELFunction.java` file within the `beetl-spring-classic` integration module. When the SpELFunction is registered and used to process user-controllable input without proper neutralization, an attacker can inject malicious SpEL expressions. This can be exploited remotely over the network without authentication to achieve arbitrary code execution or unauthorized data access. As of the advisory date, no official patch has been released by the maintainer.

Affected products

  • xiandafu (com.ibeetl) beetl-spring-classic <= 3.20.2.RELEASE

Timeline

  • 2026-04-15: disclosed: Issue reported to the project maintainer via Gitee.
  • 2026-05-17: advisory: Vulnerability published in NVD and GitHub Advisory Database.

References

Related threats