Expression Language Injection Vulnerability in Apache Struts
CVE-2026-104711
Currently unrated
What is CVE-2026-104711?
An expression language injection vulnerability exists in Apache Struts that enables attackers to craft specific requests to inject OGNL expressions, potentially leading to remote code execution. This primarily affects applications using the legacy RESTful action mapper when the OGNL allowlist is disabled. Users are advised to update to versions 6.12.0 or 7.4.0, which mitigate this vulnerability.
Affected Version(s)
Apache Struts 2.0.0 <= 2.3.37
Apache Struts 2.5.0 <= 2.5.33
Apache Struts 6.0.0 <= 6.11.0