Server-Side Template Injection in SecureTransport's Apache Velocity mail templates
Summary
| CVE | CVE-2026-9177 |
|---|---|
| State | PUBLISHED |
| Assigner | Toreon |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-29 14:16:35 UTC |
| Updated | 2026-07-30 20:27:10 UTC |
| Description | A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker with admin privileges to inject arbitrary Java code expressions, which are executed server-side when the template is rendered (i.e., during email sending). Successful exploitation of this flaw allows an attacker to execute arbitrary code on the server that results in full host compromise. This issue affects all Axway SecureTransport versions prior 5.5-20260528 update. |
Risk And Classification
Primary CVSS: v4.0 9.4 CRITICAL from 1c6b5737-9389-4011-8117-89fa251edfb2
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.002880000 probability, percentile 0.211130000 (date 2026-08-03)
Problem Types: CWE-1336 | CWE-1336 CWE-1336 Improper neutralization of special elements used in a template engine
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 1c6b5737-9389-4011-8117-89fa251edfb2 | Secondary | 9.4 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 9.4 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
HighSub Integrity
HighSub Availability
HighCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Axway | SecureTransport | affected 5.5-20260326 5.5-20260528 SecureTransport | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.axway.com/news/4882/lang/en | 1c6b5737-9389-4011-8117-89fa251edfb2 | support.axway.com | |
| www.toreon.com/CVE-2026-9177 | 1c6b5737-9389-4011-8117-89fa251edfb2 | www.toreon.com | |
| docs.hackjiji.org/blog/cve-2026-9177-ssti-in-securetransport-mft-gateway | 1c6b5737-9389-4011-8117-89fa251edfb2 | docs.hackjiji.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.