# CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

**KEV-linked**

> As of 2026-10-10, CWE-917 (Expression Language Injection) underlies 3 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 10 tracked threats.

**Last updated:** 2026-10-10

## What is CWE-917?

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

Frameworks such as Java Server Page (JSP) allow a developer to insert executable expressions within otherwise-static content. When the developer is not aware of the executable nature of these expressions and/or does not disable them, then if an attacker can inject expressions, this could lead to code execution or other unexpected behaviors.

CWE-917 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Java.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/917.html) (CWE-917 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Confidentiality** — Read Application Data
- **Integrity** — Execute Unauthorized Code or Commands

_Source: MITRE CWE, common consequences._

## How CWE-917 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-917, published between 2021-12-10 and 2026-10-05. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 3 critical. The highest EPSS score in the set is 99.9% (CVE-2022-26134), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-917 directly or through a CVE it covers; the most recent is “Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet Exploiting 18 Known CVEs in Internet-Facing Devices” (2026-10-09). Affected products concentrate in Apache (1), Apache Software Foundation (1), Atlassian (1), among 4 vendors in total.

## Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-917, CISA KEV first, then by CVSS score.

- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228) — CISA KEV · CVSS 10 critical · EPSS 99.9% · published 2021-12-10
- [CVE-2022-26134](https://intel.threadlinqs.com/cve/CVE-2022-26134) — CISA KEV · CVSS 9.8 critical · EPSS 99.9% · published 2022-06-03
- [CVE-2026-104711](https://intel.threadlinqs.com/cve/CVE-2026-104711) — CVSS 9.8 critical · EPSS 0.8% · published 2026-10-05

## Affected vendors

- **Apache** — 1 CVE
- [Apache Software Foundation](https://intel.threadlinqs.com/vendors/apache-software-foundation) — 1 CVE
- [Atlassian](https://intel.threadlinqs.com/vendors/atlassian) — 1 CVE
- [Siemens](https://intel.threadlinqs.com/vendors/siemens) — 1 CVE

## Threat activity

10 tracked threats cite CWE-917:

- [Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet Exploiting 18 Known CVEs in Internet-Facing Devices](https://intel.threadlinqs.com/threat/TL-2026-3062) — HIGH · 2026-10-09
- [Apache Struts Vulnerabilities Enable Remote Code Execution and Denial of Service (CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714)](https://intel.threadlinqs.com/threat/TL-2026-2982) — HIGH · 2026-10-06
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL · 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH · 2026-09-04
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH · 2026-08-21
- [GitHub Actions Workflow Injection in Snowflake .NET Connector Repo Exposed Jira Credentials](https://intel.threadlinqs.com/threat/TL-2026-2051) — HIGH · 2026-08-17
- [CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns](https://intel.threadlinqs.com/threat/TL-2026-1885) — HIGH · 2026-08-05
- [NadMesh Botnet Hunts Exposed AI Services (ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio) for Credentials and MCP Tool Access](https://intel.threadlinqs.com/threat/TL-2026-1455) — HIGH · 2026-07-17
- [Aquatic Panda (Earth Lusca) APT - Log4Shell Exploitation and Multi-Platform Backdoor Campaigns Targeting 17 Countries](https://intel.threadlinqs.com/threat/TL-2026-0986) — CRITICAL · 2026-06-28
- [APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain Targeting](https://intel.threadlinqs.com/threat/TL-2026-0292) — HIGH · 2026-03-27

## Mitigations

- **Architecture and Design**: Avoid adding user-controlled data into an expression interpreter when possible.
- **Implementation**: If user-controlled data must be added to an expression interpreter, one or more of the following should be performed: Validate that the user input will not evaluate as an expression Encode the user input in a way that ensures it is not evaluated as an expression
- **System Configuration, Operation**: The framework or tooling might allow the developer to disable or deactivate the processing of EL expressions, such as setting the isELIgnored attribute for a JSP page to "true".

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis** (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-77 Command Injection](https://intel.threadlinqs.com/cwe/CWE-77)
- [CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine](https://intel.threadlinqs.com/cwe/CWE-1336)
- [CWE-74 Injection](https://intel.threadlinqs.com/cwe/CWE-74)

Canonical: https://intel.threadlinqs.com/cwe/CWE-917
Source definition: https://cwe.mitre.org/data/definitions/917.html
Detection rules and IOCs for threats exploiting CWE-917 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
