{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/alfresco/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:alfresco:activiti:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-91145"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Activiti (\u003c= 7.1.0.M6)"],"_cs_severities":["high"],"_cs_tags":["expression-injection","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Alfresco"],"content_html":"\u003cp\u003eActiviti through 7.1.0.M6 contains a critical vulnerability where the engine fails to properly validate hash-brace deferred expressions provided in process variables. This flaw allows an attacker to bypass existing expression filtering mechanisms. An attacker can inject malicious SpEL (Spring Expression Language) expressions starting with the \u0026quot;#{ \u0026quot; sequence into process variables. These variables are persisted by the application and later evaluated within the full Spring application context whenever a mail task is triggered that utilizes variable-backed body fields. Successful exploitation allows for unauthorized method invocation on application beans, potentially leading to arbitrary code execution or unauthorized access to sensitive application data. Defenders should focus on identifying inputs that contain the \u0026quot;#{\u0026quot; sequence and monitoring for unexpected Spring bean method invocations during process engine execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-91145 allows remote attackers to execute arbitrary methods within the Spring application context. This could result in full application compromise, unauthorized data exfiltration, or modification of business processes managed by the Activiti engine. Organizations using affected versions of Activiti to manage sensitive workflows are at high risk of internal unauthorized command or function execution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade to a version of Activiti that provides a security patch for CVE-2026-91145.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on all process variables, specifically looking for and sanitizing the \u0026quot;#{ \u0026quot; pattern before the data reaches the persistence layer.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP requests containing the \u0026quot;#{\u0026quot; sequence, which may indicate an attempt to inject malicious expressions into process variables.\u003c/li\u003e\n\u003cli\u003eReview and restrict access to the Activiti management interface to prevent unauthorized process variable modification.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T23:36:59Z","date_published":"2026-09-14T23:36:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-activiti-expression-injection/","summary":"Activiti through 7.1.0.M6 contains an expression injection vulnerability in process variables that allows unauthenticated method invocation on application beans during mail task execution.","title":"CVE-2026-91145 Expression Injection in Activiti","url":"https://feed.craftedsignal.io/briefs/2026-09-activiti-expression-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Alfresco","version":"https://jsonfeed.org/version/1.1"}