Skip to content
THREATWIRE

CVE

MediumNo PoC

CVE-2026-104711

OGNL injection in the legacy RESTful action mapper

Apache Struts S2-075 says a crafted request can inject an OGNL expression through the legacy RESTful action mapper and may lead to remote code execution. Apache rates it Moderate. Fixed in 7.4.0 and 6.12.0. No CVSS score is published yet. Not in CISA KEV.

CVSS
Unknown
Vector
Not recorded
Class
RCE
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Apache
Products
Apache Struts
Affected
Struts 2.0.0 through 2.3.37 (EOL); 2.5.0 through 2.5.33 (EOL); 6.0.0 through 6.11.0; 7.0.0 through 7.3.0 only when the OGNL allowlist is disabled.
Fixed
Struts 7.4.0 or later, or Struts 6.12.0 or later on the 6.x line.
CWE
Not recorded
Published
5 Oct 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-104711 is described in Apache Struts Security Bulletin S2-075. When an application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Apache rates the maximum security impact as Moderate.

Applications that use the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected. On Struts 7, the issue applies only when the OGNL allowlist is disabled; that allowlist is enabled by default.

Affected ranges named by Apache are Struts 2.0.0 through 2.3.37 (EOL), 2.5.0 through 2.5.33 (EOL), 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0 under the allowlist-disabled condition. The recommended fix is Struts 7.4.0 or later, or Struts 6.12.0 or later on the 6.x maintenance line. The legacy RESTful action mappers are deprecated; Apache recommends migrating to the Struts REST plugin. As a workaround without upgrading, use the default action mapper, the restful2 mapper, or the REST plugin instead of the legacy RESTful mapper.

Apache has not published a CVSS score for this CVE. As of this draft, NVD and CVE.org have no populated record, GitHub Security Advisories return no GHSA, and CISA KEV does not list the CVE. ThreatWire has not confirmed a public PoC tagged to this CVE id. Exploitation in the wild is not confirmed by Apache or CISA.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-104711