CVE-2026-11561

CRITICAL

SSTI in Soagen Informatics' Apinizer

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-11561. PoCs published by alperenkesk.

AI-analyzed exploit summary This repository contains a Nuclei template for detecting Apinizer versions vulnerable to CVE-2026-11561 (SSTI/RCE). It extracts version information from the admin panel's JavaScript file and matches it against known vulnerable versions.

Description

Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Apinizer allows Code Injection. This issue affects Apinizer: from 2026.04.0 before 2026.04.6.

Exploits (1)

nomisec SCANNER
by alperenkesk · poc
https://github.com/alperenkesk/CVE-2026-11561

This repository contains a Nuclei template for detecting Apinizer versions vulnerable to CVE-2026-11561 (SSTI/RCE). It extracts version information from the admin panel's JavaScript file and matches it against known vulnerable versions.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apinizer < 2026.04.6
No auth needed
Prerequisites: access to the Apinizer admin panel
mistral-large-3 · analyzed Jun 21, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0045
EPSS Percentile 36.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-917
Status published
Products (1)
Soagen Informatics Technologies Software and Consulting Inc./Apinizer 2026.04.0 - 2026.04.6
Published Jun 11, 2026
Tracked Since Jun 11, 2026