External risk intelligence

Apache Struts Expression Language Injection Leads to Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-104711

Apache Struts is a framework widely used for building internet-facing web applications. While this specific vulnerability requires the legacy RESTful action mapper to be enabled, the underlying product is fundamentally designed to handle HTTP requests at the application layer, making it commonly deployed in web-facing roles.

Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in certain configurations of Apache Struts, a framework used for web applications. This issue, if exploited, could allow an attacker to execute arbitrary code on affected systems. While specific configurations are required for this to be exploitable, its presence in a widely used framework warrants attention.

  • Code injection flaw in Apache Struts.
  • Framework widely used for internet-facing applications.
  • Confirm relevance and understand potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could send a specially crafted request to an application using the legacy RESTful action mapper in Apache Struts. If the application has disabled the OGNL allowlist, this request could inject an expression language statement, potentially leading to remote code execution.

  • No authentication or special access needed.
  • Injecting malicious OGNL expression via crafted request.
  • Potential for remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a crafted request could inject an OGNL expression into an application using the legacy RESTful action mapper, potentially leading to remote code execution. This could affect the application's service behavior and allow unauthorized system access.

  • System data and service behavior.
  • Via crafted HTTP requests.
  • Remote code execution is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The potential for remote code execution through Expression Language Injection in Apache Struts primarily impacts application owners and platform teams responsible for web applications built with the framework. The first practical step is to identify all instances of Apache Struts within your environment, specifically checking if the legacy RESTful action mapper is enabled and if the OGNL allowlist is disabled. This will help determine exposure and prioritize remediation efforts by accountable owners.

  • Application owners must verify Struts configuration.
  • Confirm reachability and business criticality of affected systems.
  • Plan upgrades during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Apache Struts?

Apache Struts is a popular open-source framework used by developers to create enterprise-level Java web applications. It helps organize the flow of web traffic, manages form data, and simplifies the connection between a web browser and server-side logic. Because it sits at the core of many web interfaces, it is a common choice for building systems that need to process complex HTTP requests.

What does CVE-2026-104711 mean?

This CVE refers to an Expression Language Injection, specifically categorized as CWE-917. This weakness occurs when a software component treats untrusted user input as executable code within an expression language, such as OGNL in Struts. In this specific case, an attacker can manipulate this feature to force the server to run unauthorized commands, potentially leading to a full system compromise.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted HTTP request to a server that has the legacy RESTful action mapper enabled. Crucially, the vulnerability does not trigger if you are using default configurations, the restful2 mapper, or the Struts REST plugin. Furthermore, in Struts 7, the bug is only active if the OGNL allowlist has been manually disabled.

Do I need to worry about this vulnerability?

You should investigate if your infrastructure hosts Apache Struts applications. According to Halo Surface Signal, Struts is frequently used for internet-facing web applications, which makes the attack surface potentially large. If your applications are reachable from the internet and use the legacy components mentioned in the advisory, they are at higher risk of being targeted by unauthorized actors.

What are the first steps to address this?

Start by auditing your environment to locate all instances of Apache Struts. Verify your configuration to see if the legacy RESTful action mapper is currently in use and check the status of your OGNL allowlist. The primary fix is to upgrade your framework to version 6.12.0 or 7.4.0, so you should prioritize these updates for any systems identified as having the vulnerable configuration enabled.

References