Expression Language Injection Vulnerability in Apache Struts
CVE-2026-104711

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 October 2026

What is CVE-2026-104711?

An expression language injection vulnerability exists in Apache Struts that enables attackers to craft specific requests to inject OGNL expressions, potentially leading to remote code execution. This primarily affects applications using the legacy RESTful action mapper when the OGNL allowlist is disabled. Users are advised to update to versions 6.12.0 or 7.4.0, which mitigate this vulnerability.

Affected Version(s)

Apache Struts 2.0.0 <= 2.3.37

Apache Struts 2.5.0 <= 2.5.33

Apache Struts 6.0.0 <= 6.11.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LeaveSong
.