← back
CVE-2026-11561criticalCWE-917

SSTI in Soagen Informatics' Apinizer

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.8epss 0.4%
from disclosure to weapon10 days
Published on NVDJun 11
1st PoC+10d
exploitation probability
0.4%top 63% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.