Published on October 6, 2026

Apache Struts Vulnerabilities Enable Remote Code Execution, DoS and Data Disclosure


Severity

High

Detail

Apache has disclosed four security vulnerabilities affecting Apache Struts applications. The vulnerabilities could allow remote code execution (RCE), denial-of-service (DoS), and cross-user data disclosure, depending on application configuration and feature usage. The recommended fixes are Apache Struts 7.4.0 or later or 6.12.0 or later for organizations remaining on the 6.x maintenance branch.

The most severe vulnerability, CVE-2026-104711, affects the legacy RESTful action mapper and could allow attackers to inject OGNL expressions through crafted requests, potentially resulting in remote code execution. Applications using the default mapper, restful2 mapper, or REST plugin are not affected by this issue. The vulnerability affects Struts 2.x, 6.x, and certain 7.x deployments where the OGNL allowlist has been disabled.

CVE-2026-104712 is a denial-of-service vulnerability affecting applications that bind request parameters to java.math.BigDecimal properties and render those values through the Struts tag library. A specially crafted request could trigger excessive CPU and bandwidth consumption.

CVE-2026-104713 affects the optional REST plugin and could allow attackers to trigger memory exhaustion by sending oversized request bodies, potentially causing service disruption.

CVE-2026-104714 affects localized message formatting functionality. Concurrent requests may cause one user’s data to appear in another user’s response or trigger application errors, potentially resulting in unintended data disclosure.

CVE IDSummarySeverity
CVE-2026-104711OGNL injection vulnerability in the legacy RESTful action mapper that could lead to remote code execution.8.1 (Important)
CVE-2026-104712Denial-of-service vulnerability involving BigDecimal rendering, allowing resource exhaustion through crafted requests.7.5 (Important)
CVE-2026-104713Unbounded request-body processing vulnerability in the REST plugin that could lead to memory exhaustion and denial of service.Important
CVE-2026-104714Localized message formatting vulnerability that could result in cross-user data disclosure or application errors.Moderate

Affected Products

The vulnerabilities affect various Apache Struts versions depending on the vulnerable feature in use:

  • Apache Struts 2.x
  • Apache Struts 6.x
  • Apache Struts 7.x

Organizations should review the specific affected version ranges and determine whether vulnerable components such as the legacy RESTful action mapper, REST plugin, or affected rendering features are enabled within their deployments.

Recommendation

Organizations should implement the following measures:

  • Upgrade to Apache Struts 7.4.0 or later.
  • Upgrade to Apache Struts 6.12.0 or later if remaining on the 6.x maintenance branch.
  • Review application configurations to identify use of the legacy RESTful action mapper.
  • Ensure the OGNL allowlist remains enabled where supported.
  • Configure request size limits on reverse proxies, web servers, and servlet containers.
  • Review applications that process large BigDecimal values and implement input validation where appropriate.
  • Monitor applications for unusual memory consumption, excessive request sizes, and unexpected errors.

Source

https://cyberpress.org/apache-struts-vulnerabilities/

https://access.redhat.com/security/cve/cve-2026-104711

https://access.redhat.com/security/cve/cve-2026-104712

https://nvd.nist.gov/vuln/detail/cve-2026-104711

https://nvd.nist.gov/vuln/detail/cve-2026-104712

https://nvd.nist.gov/vuln/detail/cve-2026-104713

https://nvd.nist.gov/vuln/detail/cve-2026-104714