CVE-2026-11561
CRITICAL
9.8
CVSS 3.1
Description
Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection.
This issue affects Apinizer: from 2026.04.0 before 2026.04.6.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Soagen Informatics Technologies Software and Consulting Inc. | Apinizer | — | 2026.04.0 < 2026.04.6 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-917 | cna | CWE-917 Improper neutralization of special elements used in an expression language statement ('expression language injection') |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |