CVE-2026-11561CWE-917
SSTI in Soagen Informatics' Apinizer
Critical · published June 11, 2026
What it is
Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection.
This issue affects Apinizer: from 2026.04.0 before 2026.04.6.
The record
Technical detail
- CVSS v3.1
- 9.8 · CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00449 · 37.6th percentile
- Weakness
- CWE-917 · Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
- Published
- 2026-06-11T12:28Z
EPSS history
Timeline