CVE-2026-42555: Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users
Multiple classes evaluate Spring Expression Language (SpEL) expressions from user-supplied input using StandardEvaluationContext, which provides unrestricted access to Java types and methods. An authenticated user with the ADMIN role can achieve Remote Code Execution and credential exfiltration.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-42555 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →