News

Struts legacy REST mapper accepts OGNL code

Louis Stowasser
Louis Stowasser
Friday 9 October 2026
Struts legacy REST mapper accepts OGNL code
Struts legacy REST mapper accepts OGNL code

CVE-2026-104711 is an expression-language injection in Apache Struts, the open-source Java MVC framework used to route HTTP requests into server-side application actions. It matters chiefly to teams maintaining established Java web applications on servlet containers or application servers: the framework supports environments including WebLogic, WebSphere, JBoss and WildFly, and is often packaged as a web archive.

The vulnerable component is not Struts’ normal request routing. It is the legacy RestfulActionMapper, an optional mapper that derives an action name from part of the request URI. A remote, unauthenticated attacker can craft that input so it contains an OGNL expression. OGNL is Struts’ expression language; when hostile input reaches expression evaluation, it can potentially become server-side code execution with the application’s privileges. Apache’s advisory describes exactly that precondition and outcome.

A narrow configuration decides exposure

Applications using the default action mapper, restful2, or the Struts REST plugin are not affected. Struts 7 deployments are affected only where the OGNL allowlist has been disabled; it is enabled by default. That makes inventory alone insufficient: teams need to inspect Struts configuration and establish whether the legacy mapper is selected, rather than assuming every Java service carrying the dependency is exposed.

Apache lists affected releases as 2.0.0 through 2.3.37, 2.5.0 through 2.5.33, 6.0.0 through 6.11.0, and 7.0.0 through 7.3.0 under that disabled-allowlist condition. The 2.x branches are end of life, so there is no safe point-release destination within them. This is most likely to concern enterprises and public-sector or commercial organisations still operating long-lived Java portals, internal applications, and customer-facing services built on older framework conventions.

The patch validates the route-derived name

The fixed code stops treating the URI fragment as an action name without scrutiny. Instead, it normalizes the value through cleanupActionName; an action name that does not match the configured allowed-name pattern becomes the configured default action. This is the essential boundary the legacy mapper previously lacked:

-        String actionName = uri.substring(1, nextSlash);
+        String actionName = cleanupActionName(uri.substring(1, nextSlash));

+    protected String cleanupActionName(final String rawActionName) {
+        if (allowedActionNames.matcher(rawActionName).matches()) {
+            return rawActionName;
+        } else {
+            return defaultActionName;
+        }
+    }

Patches are available in Struts 6.12.0 and 7.4.0. Upgrade to the appropriate fixed line, test conventional action routes, and remove the legacy mapper where possible; switching to the default mapper, restful2, or the REST plugin is the documented workaround. Apache says the change is backward compatible for conventional action names. The release bulletin record indicates the fixed releases were available October 2, 2026.

No exploitation signal yet

Apache rates the issue Moderate, while the CISA ADP enrichment assigns CVSS 9.8 Critical; Apache’s advisory does not publish a numerical score. As of October 9, 2026, no exploitation in the wild and no public proof of concept or exploit code had been confirmed; CISA’s CVE record marks exploitation as none. It is also not listed in CISA’s Known Exploited Vulnerabilities catalogue.

Treat that absence as time to verify mapper configuration and upgrade, not as a reason to defer. SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs, which is useful when legacy framework paths are the deciding factor.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203