EximeeBPMS 1.4.0: security, compliance, and predictable changes for regulated institutions

Eximee Team
Published 23 Sep, 2026

The latest release of EximeeBPMS 1.4.0 constitutes another step in delivering the changes previously announced in the public product roadmap and on the project’s support page. This version focuses on closing all published security notices for Maven dependencies in the Community Edition, as well as expanding the platform’s capabilities in event-driven architecture, process history control, and the current technological baseline.

In light of these changes, what matters most for regulated institutions is not only the scope of the delivered features, but also the predictability of actions taken and the transparency of communication regarding changes that affect the security, maintenance, and compliance of production environments.

What you should know:

  • The EximeeBPMS 1.4.0 release eliminates technical debt by completely removing the deprecated CMMN standard, closes 100% of published security notices for Maven dependencies (resolving a total of 38 CVE vulnerabilities) for the Community Edition, and transitions to a Java 21 / Jakarta EE baseline.
  • Introducing the Transactional Outbox pattern in Business Events enables lossless integration with microservices architecture—including Apache Kafka, thanks to an out-of-the-box integration plugin (requiring no custom implementation)—while selective history level configuration allows for reduced database growth in high-volume transaction environments.
  • Technical details are available in the release notes and the update guide.

Timeline of announced changes

On April 17, 2025, a plan detailing components scheduled for deprecation and changes to be delivered in upcoming releases was published on the project’s Support page. From that moment on, platform development proceeded strictly according to the publicly announced path.

Releases from the 1.3.x line initiated the cleanup of selected platform components and laid the groundwork for subsequent changes, whereas version 1.4.0 executes the final stage of previously announced actions, delivering both functional updates and deprecations communicated to users before.

For institutions subject to compliance requirements, this is of paramount importance—the ability to track changes from announcement to delivery mitigates risks associated with unexpected technological shifts and enables better planning for production environment updates.

What has been delivered in version 1.4.0

Planned deprecations and removals

One of the areas covered by the changes is CMMN (Case Management Model and Notation), a standard used to model unstructured, ad-hoc business processes. Version 1.4.0 removes:

  • the CMMN engine,
  • tables related to CMMN,
  • selected columns in ACT_RU_* and ACT_HI_* structures,
  • support for older application servers, Tomcat 9 and WildFly 26,
  • support for the UUIDv1 generator (replaced by default with UUIDv7).

It is worth noting that development of CMMN was concluded by Camunda as early as 2020, and the standard was also omitted from the architecture of Camunda 8. Similarly, the recommended pattern in EximeeBPMS for unstructured processes has become BPMN 2.0 coupled with microservices architecture.

Security

Version 1.4.0 delivers patches covering vulnerabilities associated with security notices, bringing the security level of the Community Edition to parity with the Commercial Edition.

Combined with existing mechanisms such as Script Guard (a feature that controls and blocks the execution of dangerous or unauthorized scripts within processes) and an ongoing dependency analysis process, this change represents a crucial element in the long-term maintenance of the platform in regulated environments.

From the perspective of security teams, the single most important aspect of this release is the closure of all six published security notices for the Community Edition, resolving a total of 38 CVE vulnerabilities in Maven dependencies. In BPMS-class systems, where processes integrate sensitive financial data, a lack of patch parity between the free and commercial editions often blocks deployments. Therefore, in version 1.4.0, we provide banking architectures with Zero Known Vulnerabilities in Maven dependencies right at the start of migration. As a result, organizations using EximeeBPMS can ground their future development plans on an up-to-date, actively maintained security baseline.
– Robert Mastalerek, Senior Fullstack Developer on the EximeeBPMS team

Business Events

EximeeBPMS 1.4.0 also introduces native Business Events. This new functionality operates based on the Transactional Outbox pattern—a mechanism that guarantees data consistency by persisting the event in the same database transaction as the business state change. Consequently, it becomes possible to publish business events without the need to build custom integration layers based on process history analysis. Events can be forwarded both to Apache Kafka and to custom publishing mechanisms. This allows the process engine to act as a reliable source of events in architectures built around asynchronous data exchange.

Process History

Version 1.4.0 also expands process history configuration options. Administrators can exclude selected process definitions from history while maintaining the active history level for all other processes executed by the engine. This approach allows for better control over stored historical data volume and aligns configurations with organizational data retention requirements.

Technological baseline

The 1.4.0 release defines the platform’s current technological baseline:

  • Java 21 remains the required runtime environment,
  • Compatibility with Java 25 has been verified in CI,
  • The platform operates exclusively in the Jakarta environment,
  • Supported application server environments have been updated.

WebApps remain aligned with the public product roadmap, where details regarding the future direction of EximeeBPMS development are also available.

Impact on regulated institutions

For teams responsible for compliance, security, and production environment maintenance, version 1.4.0 brings several key benefits:

Change Significance for compliance and security
Security notices closure Risk mitigation regarding previously published security notices
Business Events Improved integration with event-driven architectures
Selective process history Greater control over data retention
Java 21 / Java 25 Up-to-date technological baseline
Announced removals Predictable change management process

Migrating from 1.3.0 to 1.4.0

Before upgrading to version 1.4.0, special attention should be paid to several changes that may impact existing environments and the migration process:

  • removal of CMMN,
  • modifications and adjustments to MSSQL database structures (including updates to selected column types),
  • Java 21 requirement as the runtime environment.

A detailed description of the upgrade process can be found in the documentation:

Conclusions

The EximeeBPMS 1.4.0 release represents, above all, the consistent delivery of promises and previously announced changes. This version aligns security levels between the Community and Commercial editions while establishing a modern technological baseline that fully meets the rigorous demands of regulated institutions. By enriching the platform with essential compliance-supporting features—such as Business Events and selective process history management—it guarantees organizations greater control, stability, and predictability for their production environments.

 

FAQ

Why is version 1.4.0 important for regulated institutions?

Version 1.4.0 focuses on delivering changes previously announced in the public product roadmap and project communications. It includes closing all six published security notices for Maven dependencies in the Community Edition, expanding platform capabilities in event-driven architecture, offering new options for process history management, and establishing a current technological baseline grounded in Java 21 and the Jakarta environment.

What does closing all six security notices for Community Edition mean?

It means delivering patches for all six published security notices regarding Maven dependencies and eliminating 38 CVE vulnerabilities affecting the Community Edition. As a result, the security level of the Community Edition has been brought to parity with the Commercial Edition. Combined with mechanisms like Script Guard and ongoing dependency analysis, this supports the long-term maintenance of regulated environments.

Does version 1.4.0 introduce changes related to CMMN?

Yes. In version 1.4.0, the CMMN engine and associated infrastructure elements—including CMMN-related tables and selected database structures—have been removed. These changes were previously announced in the public product roadmap.

What are Business Events in EximeeBPMS 1.4.0?

Business Events is a new feature that enables the publishing of business events without building custom integration layers based on process history analysis. The mechanism relies on the Transactional Outbox pattern and supports event-driven architectures used in enterprise environments.

What has changed in process history management?

Version 1.4.0 allows specific process definitions to be excluded from history while retaining the active history level for remaining processes run by the engine.

What are the technology requirements for EximeeBPMS 1.4.0?

Java 21 remains the required runtime environment for the platform, and compatibility with Java 25 has been verified in CI processes. EximeeBPMS 1.4.0 runs exclusively in the Jakarta environment. Detailed information on technology requirements can be found in the documentation.

Does version 1.4.0 require changes during migration from 1.3.0?

Yes. Organizations planning an upgrade should pay particular attention to:

  • removal of CMMN,
  • database structure changes,
  • Java 21 runtime environment requirement.

A detailed breakdown of these changes is available in the guide Update from 1.3.0 to 1.4.0.


Sources

  1. EximeeBPMS: Roadmap – https://eximeebpms.org/#roadmapa
  2. EximeeBPMS: Release notes 1.4.0 – https://docs.eximeebpms.org/manual/latest/release-notes/release-notes-1.4.0/
  3. EximeeBPMS: Update from 1.3.0 to 1.4.0 – https://docs.eximeebpms.org/manual/latest/update/1.3-to-1.4/
  4. EximeeBPMS: Support – https://eximeebpms.org/support/
  5. Camunda: How CMMN never lived up to its potential – https://camunda.com/blog/2020/08/how-cmmn-never-lived-up-to-its-potential/
  6. EximeeBPMS: Business Events – https://docs.eximeebpms.org/manual/latest/user-guide/process-engine/business-events/
  7. EximeeBPMS: History – https://docs.eximeebpms.org/manual/latest/user-guide/process-engine/history/
  8. EximeeBPMS: Security Instructions – https://docs.eximeebpms.org/manual/latest/user-guide/security/
  9. EximeeBPMS: Tech Stack – https://docs.eximeebpms.org/manual/latest/introduction/tech-stack/
  10. EximeeBPMS: Script Guard – https://docs.eximeebpms.org/manual/latest/user-guide/process-engine/script-guard/
  11. EximeeBPMS: Script Guard and Backpressure: how EximeeBPMS addresses RCE and overload risks in banking – https://eximeebpms.org/blog/script-guard-and-backpressure-how-eximeebpms-addresses-rce-and-overload-risks-in-banking/

Authors

Eximee Team