CVE-2026-91145: Activiti

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task uses variable-backed body fields, enabling method invocation on application beans.

Affected products

  • Activiti Activiti: up to and including 7.1.0.M6

Published 2026-09-14. Last modified 2026-09-24.