CVE-2026-104711 Overview
CVE-2026-104711 is an Object-Graph Navigation Language (OGNL) expression injection vulnerability in Apache Struts. The flaw exists in the legacy RESTful action mapper, where crafted requests can inject OGNL expressions. Successful exploitation allows unauthenticated attackers to achieve remote code execution on affected servers.
The vulnerability affects Apache Struts versions 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0. Struts 7 is only vulnerable when the OGNL allowlist is disabled, which is not the default configuration. Applications using the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected.
Critical Impact
Unauthenticated remote attackers can execute arbitrary code on Apache Struts applications configured with the legacy RESTful action mapper.
Affected Products
- Apache Struts 2.0.0 through 2.3.37
- Apache Struts 2.5.0 through 2.5.33
- Apache Struts 6.0.0 through 6.11.0 and 7.0.0 through 7.3.0 (when OGNL allowlist is disabled)
Discovery Timeline
- 2026-10-05 - CVE-2026-104711 published to the National Vulnerability Database (NVD)
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-104711
Vulnerability Analysis
The vulnerability is categorized as an Expression Language Injection flaw [CWE-917]. Apache Struts uses OGNL as its expression language to bind HTTP request parameters to backend Java objects. When the legacy RESTful action mapper processes request URIs, it fails to properly neutralize special characters that form OGNL expressions.
An attacker crafts a request targeting the vulnerable mapper and embeds an OGNL expression within the URI or parameters. The Struts framework evaluates the expression within the application's Java Virtual Machine (JVM), granting the attacker code execution in the context of the Struts process.
The attack requires no authentication, no user interaction, and can be launched remotely over the network. This matches the OGNL injection pattern seen in historical Struts advisories such as S2-045 and S2-057.
Root Cause
The root cause is insufficient input sanitization in the legacy RESTful action mapper. The mapper passes attacker-controlled portions of the request into the OGNL evaluation pipeline without enforcing the expression allowlist. In Struts 7, the default OGNL allowlist blocks dangerous constructs, which is why Struts 7 deployments are vulnerable only when administrators explicitly disable the allowlist.
Attack Vector
Attackers reach the vulnerable code path by sending HTTP requests to applications that have enabled the legacy RESTful action mapper via Struts configuration. The crafted payload contains OGNL syntax that resolves to Java reflection calls, invoking methods such as java.lang.Runtime.exec() to launch arbitrary system commands. See the Apache Commons S2-075 Advisory and the OpenWall OSS Security Discussion for additional technical context.
No verified public proof-of-concept has been published in the enriched data. Describing the exact payload structure requires referencing vendor advisories once released.
Detection Methods for CVE-2026-104711
Indicators of Compromise
- HTTP requests containing OGNL syntax tokens such as %{, #_memberAccess, @java.lang.Runtime@, or ognl.OgnlContext in URIs, headers, or parameters.
- Unexpected child processes spawned by the Java application server, including sh, bash, cmd.exe, powershell.exe, or curl executed by the Struts JVM.
- Outbound network connections from the application server to attacker-controlled infrastructure immediately following requests to RESTful action endpoints.
- Modified or newly created JavaServer Pages (JSP) files or web shells inside the application's deployment directory.
Detection Strategies
- Inspect web server and application logs for requests to RESTful mapper endpoints containing OGNL metacharacters or Java class references.
- Deploy a Web Application Firewall (WAF) rule that blocks OGNL expression patterns in request URIs and parameters.
- Correlate process execution telemetry from Java application servers with inbound HTTP traffic to identify command execution originating from web requests.
Monitoring Recommendations
- Monitor Apache Struts configuration files for the presence of struts.mapper.class=org.apache.struts2.dispatcher.mapper.RestfulActionMapper and flag any deployments that disable the OGNL allowlist in Struts 7.
- Alert on new file writes to application webapps/ directories by the Java process.
- Track egress traffic from middle-tier Java servers to uncategorized or newly observed external hosts.
How to Mitigate CVE-2026-104711
Immediate Actions Required
- Upgrade Apache Struts to version 6.12.0 or 7.4.0, which contain the official fix for CVE-2026-104711.
- Inventory all Struts deployments and identify applications using the legacy RESTful action mapper.
- Verify that the OGNL allowlist is enabled on all Struts 7 instances and remove any configuration overrides that disable it.
- Review application and WAF logs for the past 30 days for signs of OGNL injection attempts against RESTful endpoints.
Patch Information
Apache has released fixed versions in Struts 6.12.0 and Struts 7.4.0. These releases remediate the improper neutralization in the legacy RESTful action mapper. Operators of Struts 2.3.x and 2.5.x branches, which also fall within the affected range, should migrate to a supported release line because those branches may not receive back-ported fixes.
Workarounds
- Switch the application configuration from the legacy RESTful action mapper to the default action mapper or to the restful2 mapper, both of which are not affected.
- Remove or disable the Struts REST plugin configuration entries that enable the legacy mapper where it is not required.
- Enforce the OGNL allowlist on Struts 7 by ensuring struts.ognl.allowlist.enable=true remains set.
- Place a WAF in front of exposed Struts applications and block requests containing OGNL expression metacharacters until patching completes.
# Verify Struts version in a deployed WAR file
unzip -p app.war WEB-INF/lib/struts2-core-*.jar | \
grep -a 'Implementation-Version'
# Confirm the OGNL allowlist is enabled (Struts 7)
grep -R "struts.ognl.allowlist.enable" WEB-INF/classes/struts.properties
# Identify use of the legacy RESTful mapper
grep -R "RestfulActionMapper" WEB-INF/classes/ WEB-INF/
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.