CVE-2026-42555
Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.valtimo:contract from 13.4.0 to before 13.23.0 evaluate Spring Expression Language (SpEL) expressions from user-supplied input using StandardEvaluationContext, which provides unrestricted access to Java types and methods. An authenticated user with the ADMIN role can achieve Remote Code Execution and credential exfiltration. This vulnerability is fixed in com.ritense.valtimo:document 2.32.0, com.ritense.valtimo:case 13.23.0, and com.ritense.valtimo:contract 13.23.0.
Published:May 14, 2026
Last Modified:May 17, 2026
EPS:May 14, 2026
EPSS Score:0.00232
CVSS Score:9.1
Affected Products
Vendor
Product
Action
Vendor
Com.ritense.valtimo
Product
Case
Com.ritense.valtimo
Case
Vendor
Com.ritense.valtimo
Product
Contract
Com.ritense.valtimo
Contract
Vendor
Com.ritense.valtimo
Product
Document
Com.ritense.valtimo
Document
Vendor
Valtimo-platform
Product
Valtimo
Valtimo-platform
Valtimo
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
