Cyber Security News

Apache Struts Vulnerabilities Enable Remote Code Execution, DoS and Data Disclosure

Four Apache Struts vulnerabilities outlined in recent advisories expose affected applications to risks such as remote code execution, denial of service, and cross-user data disclosure.

These issues impact legacy action mapping, decimal rendering, REST request processing, and localized message formatting. Fixes are available in Struts versions 7.4.0 and 6.12.0.

The advisories, published between August 3 and September 4, 2026, identify the vulnerabilities as CVE-2026-104711 through CVE-2026-104714.

The extent of exposure varies based on application configuration and component usage, meaning not all Struts deployments are vulnerable to all four issues.

Apache Struts Vulnerabilities

CVE-2026-104711 involves OGNL (Object-Graph Navigation Language) injection in the legacy RESTful action mapper. A crafted request can inject an expression, potentially allowing remote code execution.

Affected versions include Struts 2.0.0 to 2.3.37, 2.5.0 to 2.5.33, and 6.0.0 to 6.11.0. Struts versions 7.0.0 to 7.3.0 are affected only if the OGNL allowlist is disabled.

The advisory assigns a moderate risk rating. Applications utilizing the default mapper, restful2 mapper, or Struts REST plugin are not affected.

Struts 7’s default configuration also prevents exposure as its OGNL allowlist remains enabled. Administrators can replace the legacy mapper with an unaffected alternative while preparing for an upgrade.

CVE-2026-104712 enables unauthenticated attackers to exhaust CPU and outbound network capacity through disproportionately large responses.

This flaw occurs when request parameters bind to `java.math.BigDecimal` properties, which are later rendered through the Struts tag library, causing small requests to generate responses many orders of magnitude larger.

This can lead to sustained disruption with limited attacker bandwidth. Affected releases are 2.5.14 to 2.5.33, 6.0.0 to 6.11.0, and 7.0.0 to 7.3.0.

Other numeric types, JSON plugin responses, and REST plugin responses are not impacted. A temporary workaround involves using a custom `BigDecimal` type converter that bounds the scale before rendering.

CVE-2026-104713, rated important, affects the optional REST plugin, which reads request bodies into memory without enforcing a size limit. A single oversized request can exhaust heap memory, leading to denial of service.

Affected versions include 2.1.8 to 2.3.37, 2.5.0 to 2.5.33, 6.0.0 to 6.11.0, and 7.0.0 to 7.3.0. Patched releases implement a default limit of 2,097,152 characters.

For applications requiring larger bodies, the configuration can be adjusted through `struts.rest.content.maxLength`. Until an upgrade is possible, operators should set request-size limits using reverse proxies or servlet containers.

CVE-2026-104714 impacts shared formatters used for localized messages that contain date or time arguments. Concurrent requests can interfere, causing one user’s value to appear in another user’s response or triggering server errors.

This issue can occur with ordinary traffic and no malicious intent. Exposure relates to application-defined message bundles, not messages provided with Struts. Affected versions include 2.0.0 to 2.3.37, 2.5.0 to 2.5.33, 6.0.0 to 6.11.0, and 7.0.0 to 7.3.0.

Organizations should upgrade to Struts 7.4.0 or 6.12.0. For temporary mitigation, date and time values should be preformatted before message interpolation. Teams maintaining end-of-life branches should migrate to supported releases rather than relying solely on workarounds for these vulnerabilities.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

1 hour ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

2 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

3 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

3 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

4 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

5 hours ago