Impact
A Server‑Side Template Injection flaw in the mail template system of Axway SecureTransport allows an attacker with administrative rights to inject arbitrary Java code expressions into Velocity templates. When the email is rendered this code executes on the server, giving the attacker full control of the host. The weakness is categorized as CWE-1336.
Affected Systems
Axway Stable the SecureTransport product family, specifically all releases up to and including the 5.5‑20260326 build. The vulnerability is fixed in the 5.5‑20260528 update and later versions.
Risk and Exploitability
The CVSS score of 9.4 indicates a severe security risk. The EPSS score of less than 1% reflects a low chance of exploitation in the wild, and the flaw is not yet listed in the CISA KEV catalog. The exploit path requires an attacker to possess administrative access to create or modify the Velocity mail template; once a crafted template is processed during email sending, the injected Java code runs on the server, leading to unrestricted system compromise.
OpenCVE Enrichment