CVE-2026-11561

CRITICAL

SSTI in Soagen Informatics' Apinizer

Title source: cna
STIX 2.1

Description

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0032
EPSS Percentile 23.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-917
Status published
Products (1)
Soagen Informatics Technologies Software and Consulting Inc./Apinizer 2026.04.0 - 2026.04.6
Published Jun 11, 2026
Tracked Since Jun 11, 2026