CVE-2026-11561CWE-917

SSTI in Soagen Informatics' Apinizer

Critical · published June 11, 2026

CVSS v3.1
9.8
EPSS
0%
Percentile
37.6
In the wild
Unconfirmed
What it is

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection.

This issue affects Apinizer: from 2026.04.0 before 2026.04.6.

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00449 · 37.6th percentile
Weakness
CWE-917 · Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Published
2026-06-11T12:28Z
EPSS history
Timeline
  • 11 JUN 12:28Z
    SSTI in Soagen Informatics' Apinizer
    cvelistv5