Skip to content
Rota Nacional

Cyber ·

CVE-2026-104711: OGNL injection in the legacy REST action mapper of Apache Struts

Moderate-severity advisory on an OGNL expression language injection flaw in the legacy RESTful action mapper of Apache Struts, shared on the oss-sec list on 5 October 2026, with affected version ranges listed.

The advisory describes CVE-2026-104711, an OGNL injection flaw in the legacy REST action mapper of Apache Struts. According to the text, it can be triggered in applications configured to use that component, through a specially crafted request. The stated severity is moderate. The listed affected ranges are Apache Struts 2.0.0 to 2.3.37; 2.5.0 to 2.5.33; 6.0.0 to 6.11.0; and 7.0.0 to 7.3.0. The original post was made by a project member on the oss-sec list on 5 October 2026. The received content is an automatic translation and is truncated, so it does not include complete mitigation guidance. To verify the affected versions, fix status and recommendations, consult the original text on the oss-sec list and the official Apache Struts project page. Rota Nacional does not detect or fix this vulnerability, and this material does not describe a platform feature that resolves it. If your team uses AI to study the advisory, do not paste real configurations, server names, logs containing credentials or production code; replace such data with generic markers before sending.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free