CVE-2026-9177

Axway · SecureTransport

Axway SecureTransport is vulnerable to server-side template injection in its mail template functionality, allowing authenticated admins to execute arbitrary code.

Executive summary

An authenticated server-side template injection vulnerability in Axway SecureTransport allows administrators to execute arbitrary code, leading to full host compromise.

Vulnerability

The mail template engine fails to properly neutralize user-supplied input. An attacker with administrative privileges can inject malicious Java code expressions into email templates, which are then executed by the server during the rendering process.

Business impact

While this vulnerability requires administrative privileges, the outcome of a successful exploit is total host compromise. This presents a severe risk to the confidentiality, integrity, and availability of the SecureTransport environment and any data managed by the system, as reflected by the high CVSS score.

Remediation

Immediate Action: Update Axway SecureTransport to version 5.5-20260528 or the latest available maintenance release.

Proactive Monitoring: Review administrative audit logs for any suspicious modifications to mail templates or unexpected system behavior during email dispatch.

Compensating Controls: Restrict administrative access to the SecureTransport console to a limited set of trusted personnel and implement strict network segmentation for the management interface.

Exploitation status

Public Exploit Available: No (unknown)

Analyst recommendation

Organizations utilizing Axway SecureTransport should apply the provided update as soon as possible to mitigate the risk of remote code execution. Maintaining the principle of least privilege for administrative accounts is essential to preventing exploitation of this vulnerability.