Junglewise Threat Intelligence

CVE-2026-91145: Alfresco Activiti expression injection in process variables

CVE-2026-91145 · Severity: high · CVSS 7.1 · Published 2026-09-14

Executive brief

Activiti is a Business Process Management (BPM) engine used to automate workflows and business processes in Java applications. The vulnerability allows attackers to inject malicious code through process variables that bypasses security filtering, leading to arbitrary method execution on application beans when mail tasks process these variables. This could enable complete compromise of the application and its data.

Technical details

The vulnerability is an expression language (EL) injection flaw in Activiti's expression resolver. The vulnerable component fails to properly validate and filter hash-brace deferred expressions (#{...}) in process variables, allowing attackers to store arbitrary Spring EL expressions that are evaluated later in the full Spring context. When a mail task processes variable-backed body fields, these expressions are evaluated with full application bean access, enabling method invocation. The attack requires no authentication if the attacker can submit process variables through a public API, or may require existing process access in more restricted deployments. No patch status is currently indicated in the advisory.

Affected products

  • Alfresco Activiti through 7.1.0.M6

Timeline

  • 2026-09-14: disclosed

References