In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 26 Aug 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Command Execution via Unfiltered JUEL Expressions in AntFlow | |
| Weaknesses | CWE-94 |
Wed, 26 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-26T20:40:15.222Z
Reserved: 2026-08-17T00:00:00.000Z
Link: CVE-2026-75414
No data.
Status : Received
Published: 2026-08-26T21:16:41.330
Modified: 2026-08-26T21:16:41.330
Link: CVE-2026-75414
No data.
OpenCVE Enrichment
Updated: 2026-08-26T22:45:03Z
Weaknesses