CVE-2026-75414: AntFlow vulnerability
Published Aug 26, 2026
·Updated
In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.
Affected Software
1 affected component
AntFlow=2.0.0
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
An attacker needs to be able to supply input that is evaluated by ActivitiTest.java as a JUEL expression. The provided information does not specify whether authentication or any particular application role is required.