CVE-2026-34164 Details
Description
Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingService logs the full content of every incoming inbox message at INFO level. Inbox messages can contain highly sensitive information including personal data (PII), citizen identifiers (BSN), and case details. This data is exposed to anyone with access to application logs or any Valtimo user with the admin role through the Admin UI logging module. This issue has been fixed in version 13.22.0. If developers are unable to upgrade immediately, they can restrict access to application logs and adjust the log level for com.ritense.inbox to WARN or higher in their application configuration as a workaround.
A vulnerability in the Valtimo InboxHandlingService has been identified, affecting versions 13.0.0 prior to 13.21.0. The service logs the full content of incoming inbox messages at the INFO level, potentially exposing highly sensitive information such as personal data, citizen identifiers, and case details. This logged data is accessible to anyone with access to application logs, as well as Valtimo users with admin roles through the Admin UI logging module.
Users can upgrade to Valtimo version 13.22.0, where this vulnerability has been fixed. If an immediate upgrade is not possible, access to application logs can be restricted, and the log level for 'com.ritense.inbox' can be adjusted to WARN or higher in the application configuration.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 16, 2026CISA-ADP
Assessed Apr 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/generiekzaakafhandelcomponent/gzac-issues/issues/653 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/valtimo-platform/valtimo/commit/f16a1940ba7b34627c0b966f98ca78655ace9335 | [email protected] | Source CodeVendor |
| https://github.com/valtimo-platform/valtimo/pull/497 | [email protected] | Issue TrackingVendor |
| https://github.com/valtimo-platform/valtimo/releases/tag/13.22.0 | [email protected] | Release NotesVendor |
| https://github.com/valtimo-platform/valtimo/security/advisories/GHSA-hfrg-mcvw-8mch | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Valtimo | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2026 | New CVE Received | [email protected] |
Volerion