CVE-2026-9177 Details
Description
A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker with admin privileges to inject arbitrary Java code expressions, which are executed server-side when the template is rendered (i.e., during email sending). Successful exploitation of this flaw allows an attacker to execute arbitrary code on the server that results in full host compromise. This issue affects all Axway SecureTransport versions prior 5.5-20260528 update.
A Server-Side Template Injection (SSTI) vulnerability has been identified in the mail template functionality of Axway SecureTransport version 5.5-20260326. This vulnerability allows an attacker with admin privileges to inject arbitrary Java code expressions into email templates, which are executed on the server when the email is sent. Exploitation of this vulnerability could lead to arbitrary code execution on the server, resulting in a complete compromise of the host. This issue affects all Axway SecureTransport versions prior to 5.5-20260528 update.
Users are advised to update to Axway SecureTransport version 5.5-20260528 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.hackjiji.org/blog/cve-2026-9177-ssti-in-securetransport-mft-gateway | Toreon | |
| https://support.axway.com/news/4882/lang/en | Toreon | |
| https://www.toreon.com/CVE-2026-9177 | Toreon |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | Toreon |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | New CVE Received | Toreon |