CVE Explorer
CVE-2026-9177
A Server-Side Template Injection (SSTI) vulnerability was identified
in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This
flaw
allows an attacker with admin privileges to inject arbitrary Java code expressions, which are
executed server-side when the template is rendered (i.e., during email
sending). Successful exploitation of this flaw allows an attacker to
execute
arbitrary code on the server that results in full host compromise.
This
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"affected","packageName":"Apache Velocity","product":"SecureTransport","vendor":"Axway","versions":[{"lessThan":"5.5-20260528","status":"affected","version":"5.5-20260326","versionType":"SecureTransport"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a090e090598a24dceb54677e8c952a1ba89b677f7c42b7396e79ac70281b89b0 · sha256:6853eee335b71485… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.4,"baseSeverity":"CRITICAL","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpac…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a090e090598a24dceb54677e8c952a1ba89b677f7c42b7396e79ac70281b89b0 · sha256:6853eee335b71485… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1336","description":"CWE-1336 Improper neutralization of special elements used in a template engine","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a090e090598a24dceb54677e8c952a1ba89b677f7c42b7396e79ac70281b89b0 · sha256:6853eee335b71485… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["technical-description"],"url":"https://docs.hackjiji.org/blog/cve-2026-9177-ssti-in-securetransport-mft-gateway"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a090e090598a24dceb54677e8c952a1ba89b677f7c42b7396e79ac70281b89b0 · sha256:6853eee335b71485… · /containers/cna/references/2
{"tags":["vendor-advisory","mitigation","patch","customer-entitlement"],"url":"https://support.axway.com/news/4882/lang/en"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a090e090598a24dceb54677e8c952a1ba89b677f7c42b7396e79ac70281b89b0 · sha256:6853eee335b71485… · /containers/cna/references/0
{"tags":["technical-description"],"url":"https://www.toreon.com/CVE-2026-9177"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a090e090598a24dceb54677e8c952a1ba89b677f7c42b7396e79ac70281b89b0 · sha256:6853eee335b71485… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.