CVE-2026-104711

Remote Code Execution
Affects
Apache Struts
in
Apache Struts
No items found.
Versions
>=2.0.0 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <=6.11.0, >=7.0.0 <=7.3.0

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Apache Struts is a popular open-source web application framework for developing Java EE web applications. Struts 2 uses an action mapper to turn each request URI into an action name and parameters, and the legacy RestfulActionMapper (the restful mapper) reads the action name from the first path segment.

A remote code execution vulnerability (CVE-2026-104711) has been identified in the legacy RESTful action mapper of Apache Struts, which allows attackers to inject an OGNL expression through a crafted request URI that may lead to remote code execution. Only applications configured to use the legacy RESTful action mapper are affected; applications using the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected.

Per OWASP: Code Injection is the general term for attack types which consist of injecting code that is then interpreted/executed by the application. This type of attack exploits poor handling of untrusted data.

This issue affects multiple versions of Apache Struts.

‍

Details

Module Info

Vulnerability Info

This Critical-severity vulnerability is found in the org.apache.struts:struts2-core package in multiple versions of Apache Struts. When an application sets the restful action mapper, RestfulActionMapper.getMapping takes everything between the first and second slash of the servlet path as the action name and passes it on unchecked:

String uri = RequestUtils.getServletPath(request);

int nextSlash = uri.indexOf('/', 1);
if (nextSlash == -1) {
    return null;
}

String actionName = uri.substring(1, nextSlash);
// ... remaining path segments are parsed into parameters ...
return new ActionMapping(actionName, "", "", parameters);

The default DefaultActionMapper checks every action name against the struts.allowed.action.names pattern and falls back to struts.default.action.name when it does not match. RestfulActionMapper performs no such check, so a request path such as /%{1+1}/x produces an ActionMapping whose name is the raw OGNL expression %{1+1}. That attacker-controlled name is then handed to the rest of the framework, where it can be evaluated as an OGNL expression, which may lead to remote code execution by an unauthenticated remote attacker. In Struts 7 the OGNL allowlist, which is enabled by default, blocks this, so Struts 7 is only exploitable when the allowlist has been disabled.

‍

Mitigation

Only recent versions of Apache Struts are community-supported. Older lines are End-of-Life and will not receive any updates to address this issue.

Users of the affected components should apply one of the following mitigations:

  • Upgrade affected applications to a supported version of Apache Struts.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.

‍

Credits

  • LeaveSong (finder)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
Critical
ID
CVE-2026-104711
PROJECT Affected
Apache Struts
Versions Affected
>=2.0.0 <=2.3.37, >=2.5.0 <=2.5.33, >=6.0.0 <=6.11.0, >=7.0.0 <=7.3.0
NES Versions Affected
Published date
October 6, 2026
≈ Fix date
October 7, 2026
Category
Remote Code Execution
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Apache Struts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.