CVE-2026-104711

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default. Applications using the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected. This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0. Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-917

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-05: 210-05
Referenced assets2 URLs
Full discourse2 posts
  • ThreatWire@ThreatWire_

    🚨 SECURITY UPDATE: Apache Struts 7.4.0 and 6.12.0 fix four vulnerabilities (S2-075 to S2-078). ➡️ CVE-2026-104713 (Important): the REST plugin reads request bodies without a size limit, allowing heap exhaustion and denial of service. 7.4.0 adds a 2 MB default limit. ➡️ CVE-2026-104711 (Moderate): OGNL injection through the legacy RESTful action mapper, which can lead to remote code execution. On 7.x, only deployments with the OGNL allowlist disabled are affected. ➡️ CVE-2026-104712 / CVE-2026-104714 (Moderate): a BigDecimal rendering DoS and a shared date formatter race that can cause information disclosure or DoS. ⚠️ No official CVSS yet. Not in CISA KEV, and no exploitation reported. 🔴 Upgrade to Struts 7.4.0 or 6.12.0. The 2.x branches are end-of-life: plan a migration. Full breakdown 👉 https://www.threatwire.tech/news/apache-struts-7-4-0-fixes-four-security-flaws #CyberSecurity #InfoSec #ApacheStruts #Java

    01091601
    1.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Struts 7.4.0 fixes four Apache Struts vulnerabilities, including OGNL injection CVE-2026-104711 and a REST plugin DoS. Upgrade now. #ApacheStruts #Struts #CVE2026104711 #CVE2026104713 #CVE2026104714 #OGNL #JavaSecurity #Vulnerability https://securityonline.info/apache-struts-vulnerabilities-7-4-0/

    00020396
    13.0K followersView on X

Explore more