Executive brief
Axway SecureTransport, a managed file transfer gateway used for secure business data exchange, contains a vulnerability in its email template system. An attacker with administrative privileges can upload a malicious template that executes unauthorized commands on the underlying server. This could lead to a total compromise of the system, allowing the attacker to steal sensitive files, disrupt operations, or move deeper into the corporate network.
Technical details
A Server-Side Template Injection (SSTI) vulnerability exists in the mail template functionality of Axway SecureTransport. The application utilizes the Apache Velocity template engine without adequate sandboxing or input validation. An attacker with administrative privileges can upload a crafted .xhtml template containing malicious Velocity directives and Java code expressions (e.g., utilizing java.lang.Runtime). When the template is rendered during email notification events, the injected code is executed on the server. This allows for full remote code execution (RCE) and host compromise. The issue is resolved in the 5.5-20260528 update.
Affected products
- Axway SecureTransport Prior to 5.5-20260528 update
Timeline
- 2026-05-22: disclosed: Reported to Axway by Toreon
- 2026-06-02: patched: Axway released a patch and security notice
- 2026-07-29: advisory: Public disclosure and CVE publication