---
id: CVE-2026-104711
title: >-
  Improper neutralization of special elements used in an expression language
  statement ('Expression Language Injection') vulnerability in Apache Struts
summary: >-
  Improper neutralization of special elements used in an expression language
  statement ('Expression Language Injection') vulnerability in Apache Struts. If
  the application is configured to use the legacy RESTful action mapper, a
  crafted re…
severity: none
cwe:
  - CWE-917
vendor: Apache Software Foundation
product: 'org.apache.struts:struts2-core'
affected:
  - 'org.apache.struts:struts2-core >= 2.0.0 <= 2.3.37'
  - 'org.apache.struts:struts2-core >= 2.5.0 <= 2.5.33'
  - 'org.apache.struts:struts2-core >= 6.0.0 <= 6.11.0'
  - 'org.apache.struts:struts2-core >= 7.0.0 <= 7.3.0'
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:08.790'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104711'
references:
  - url: 'https://cwiki.apache.org/confluence/display/WW/S2-075'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/10/05/10'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T19:30:59.977Z'
---

## Overview

Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default. Applications using the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected.

This issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.

Users are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
