CVE-2026-104711
OGNL injection in the legacy RESTful action mapper
Apache Struts S2-075 says a crafted request can inject an OGNL expression through the legacy RESTful action mapper and may lead to remote code execution. Apache rates it Moderate. Fixed in 7.4.0 and 6.12.0. No CVSS score is published yet. Not in CISA KEV.
- CVSS
- Unknown
- Vector
- Not recorded
- Class
- RCE
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Apache
- Products
- Apache Struts
- Affected
- Struts 2.0.0 through 2.3.37 (EOL); 2.5.0 through 2.5.33 (EOL); 6.0.0 through 6.11.0; 7.0.0 through 7.3.0 only when the OGNL allowlist is disabled.
- Fixed
- Struts 7.4.0 or later, or Struts 6.12.0 or later on the 6.x line.
- CWE
- Not recorded
- Published
- 5 Oct 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-104711 is described in Apache Struts Security Bulletin S2-075. When an application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Apache rates the maximum security impact as Moderate.
Applications that use the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected. On Struts 7, the issue applies only when the OGNL allowlist is disabled; that allowlist is enabled by default.
Affected ranges named by Apache are Struts 2.0.0 through 2.3.37 (EOL), 2.5.0 through 2.5.33 (EOL), 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0 under the allowlist-disabled condition. The recommended fix is Struts 7.4.0 or later, or Struts 6.12.0 or later on the 6.x maintenance line. The legacy RESTful action mappers are deprecated; Apache recommends migrating to the Struts REST plugin. As a workaround without upgrading, use the default action mapper, the restful2 mapper, or the REST plugin instead of the legacy RESTful mapper.
Apache has not published a CVSS score for this CVE. As of this draft, NVD and CVE.org have no populated record, GitHub Security Advisories return no GHSA, and CISA KEV does not list the CVE. ThreatWire has not confirmed a public PoC tagged to this CVE id. Exploitation in the wild is not confirmed by Apache or CISA.