https://seclists.org/oss-sec/2026/q1/56: CVE-2025-68493: Apache Struts: XXE vulnerability in outdated XWork component
Published Jan 12, 2026
·Updated
Affected Software
1 affected component
Apache Struts
Frequently Asked Questions
1
What is the severity of CVE-2025-68493?
CVE-2025-68493 has been classified as a critical severity vulnerability due to its potential for data exposure and exploitation in Apache Struts.
2
How do I fix CVE-2025-68493?
To fix CVE-2025-68493, upgrade the XWork component in Apache Struts to the latest version that addresses this XXE vulnerability.
3
What systems are affected by CVE-2025-68493?
CVE-2025-68493 affects systems running Apache Struts that utilize the outdated XWork component.
4
What type of vulnerability is CVE-2025-68493?
CVE-2025-68493 is an XML External Entity (XXE) vulnerability that can lead to sensitive data disclosure.
5
What are the potential impacts of CVE-2025-68493?
The potential impacts of CVE-2025-68493 include unauthorized access to confidential information and possible server-side request forgery.