Threat reportVulnerabilityTL-2026-2982
Apache Struts Vulnerabilities Enable Remote Code Execution and Denial of Service (CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714)
Apache Struts Vulnerabilities Enable Remote Code Execution (TL-2026-2982), also tracked as S2-075, is a high-severity software vulnerability, first published 2026-10-06. It has no confirmed attribution, affects Apache Software Foundation Apache Struts (legacy RESTful action, references 4 CVEs (CVE-2026-104711, CVE-2026-104712, CVE-2026-104713), maps to 4 MITRE ATT&CK techniques (T1059, T1190, T1499.003), and is covered by 9 detection rules and 8 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 4Referenced vulnerabilities
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-2982
- Threat ID
- TL-2026-2982
- Also known as
- S2-075, S2-076, S2-077, S2-078
- Severity
- HIGH
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, finance, government administration, telecoms, health
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
How Apache Struts Vulnerabilities Enable Remote Code Execution works
The Apache Struts project fixed four vulnerabilities (S2-075 to S2-078) in Struts 7.4.0 and 6.12.0 on 2026-10-02: an OGNL injection in the legacy RESTful action mapper that can lead to remote code execution, a BigDecimal rendering denial of service, an unbounded request body read in the REST plugin, and a shared message formatter that can leak date/time values between concurrent users. No active exploitation or public PoC is reported.
On 2026-10-02 the Apache Struts project released Struts 7.4.0 and 6.12.0 (both General Availability) and published four security bulletins, S2-075 through S2-078. Cyber Security News covered the disclosure on 2026-10-06. The release announcement strongly advises all developers to upgrade. Struts 7.3.0 and 6.11.0, released 2026-08-01, are the last vulnerable releases in their lines.
CVE-2026-104711 (S2-075, rated Moderate by Apache, reporter LeaveSong) is an OGNL injection in the legacy RESTful action mapper. A crafted request can inject an OGNL expression that may lead to remote code execution. Affected versions are Struts 2.0.0-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0 and 7.0.0-7.3.0. The S2-075 bulletin attaches the condition that the OGNL allowlist is disabled to the 7.x range; the press article states the allowlist-disabled condition more broadly. Applications using the default mapper, the restful2 mapper or the Struts REST plugin are not affected. The only workaround is to switch away from the legacy RESTful action mapper.
CVE-2026-104712 (S2-076, Moderate, reporter 0xCc.zhang) is a resource-exhaustion denial of service. When request parameters bind to java.math.BigDecimal properties and are rendered through Struts tag libraries, small requests can produce responses many orders of magnitude larger. Affected versions are 2.5.14-2.5.33 (EOL), 6.0.0-6.11.0 and 7.0.0-7.3.0. Applications that do not bind BigDecimal properties, that use JSON/REST plugin responses, or that use other numeric types are unaffected. The workaround is a custom BigDecimal type converter registered in struts-conversion.properties (xwork-conversion.properties on 2.5.x) that bounds the scale before rendering.
CVE-2026-104713 (S2-077, Important, reporter n0mi1k) is a memory-exhaustion denial of service. The REST plugin reads a request body into memory with no bound, so oversized requests can exhaust the heap. Affected versions are 2.1.8-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0 and 7.0.0-7.3.0. Struts has no configuration-only fix. The patched releases add a default limit of 2,097,152 characters (2 MB), configurable with struts.rest.content.maxLength. Until upgraded, defenders should enforce a maximum request body size in the reverse proxy or servlet container.
CVE-2026-104714 (S2-078, Moderate, reporter n0mi1k) is a concurrency flaw. A message formatter is shared between concurrently served requests. When localized messages format date or time arguments, one user's value can appear in another user's response, or rendering can fail and surface as a server error. Ordinary concurrent traffic triggers it, with no malicious input needed. Affected versions are 2.0.0-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0 and 7.0.0-7.3.0. The workaround is to format date/time values before message interpolation.
The sources state no numeric CVSS score, no active exploitation, no public PoC and no network or file indicators of compromise. Apache's own ratings are Moderate (104711, 104712, 104714) and Important (104713). The HIGH severity assigned here is an analyst estimate based on the remote code execution class of CVE-2026-104711, not a source-stated score. The CVE ids themselves come from the Apache bulletins; NVD and web searches returned nothing for them at the time of research.
MITRE ATT&CK techniques used in TL-2026-2982
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.003 Application Exhaustion Flood; T1499.004 Application or System Exploitation
Affected products and versions in Apache Struts Vulnerabilities Enable Remote Code Execution
- Apache Software Foundation — Apache Struts (legacy RESTful action mapper) - CVE-2026-104711
Vulnerable versions: 2.0.0-2.3.37; 2.5.0-2.5.33; 6.0.0-6.11.0; 7.0.0-7.3.0 (with OGNL allowlist disabled)
Fixed in: 6.12.0; 7.4.0 - Apache Software Foundation — Apache Struts (BigDecimal rendering via tag libraries) - CVE-2026-104712
Vulnerable versions: 2.5.14-2.5.33; 6.0.0-6.11.0; 7.0.0-7.3.0
Fixed in: 6.12.0; 7.4.0 - Apache Software Foundation — Apache Struts REST plugin - CVE-2026-104713
Vulnerable versions: 2.1.8-2.3.37; 2.5.0-2.5.33; 6.0.0-6.11.0; 7.0.0-7.3.0
Fixed in: 6.12.0; 7.4.0 - Apache Software Foundation — Apache Struts (shared message formatter) - CVE-2026-104714
Vulnerable versions: 2.0.0-2.3.37; 2.5.0-2.5.33; 6.0.0-6.11.0; 7.0.0-7.3.0
Fixed in: 6.12.0; 7.4.0
Remediation for Apache Struts Vulnerabilities Enable Remote Code Execution
Patches
- Upgrade to Apache Struts 7.4.0 or later (requires Java 17 and JakartaEE)
- Upgrade to Apache Struts 6.12.0 or later on the 6.x maintenance line (Servlet API 3.1, JSP API 2.1, Java 8)
Immediate actions
- Inventory applications built on Apache Struts, including transitive and embedded copies, and identify any that use the legacy RESTful action mapper or the REST plugin
- Enforce a maximum request body size in the reverse proxy or servlet container in front of any endpoint that accepts request bodies (mitigates CVE-2026-104713)
- Confirm the OGNL allowlist is enabled on Struts 7.x deployments
Workarounds
- CVE-2026-104711: use the default action mapper, the restful2 mapper or the Struts REST plugin instead of the legacy RESTful action mapper
- CVE-2026-104712: register a custom java.math.BigDecimal converter that bounds scale, in struts-conversion.properties (xwork-conversion.properties on 2.5.x)
- CVE-2026-104713: enforce a request body limit at the reverse proxy or servlet container; patched versions default to 2,097,152 characters, configurable via struts.rest.content.maxLength
- CVE-2026-104714: format date/time values before passing them to localized messages and interpolate the already-formatted value
Longer-term hardening
- Migrate off the legacy RESTful action mapper to the default mapper, the restful2 mapper or the Struts REST plugin
- Move off end-of-life Struts 2.3.x and 2.5.x lines, which will not receive these fixes
- Subscribe to Apache Struts security bulletins and track the Struts release feed
CVEs associated with Apache Struts Vulnerabilities Enable Remote Code Execution
CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714
Timeline of Apache Struts Vulnerabilities Enable Remote Code Execution
- Apache Struts 7.3.0 and 6.11.0 are released; they are the latest releases affected by CVE-2026-104711 to CVE-2026-104714.
- Bulletins S2-077 (CVE-2026-104713, unbounded REST plugin request body read) and S2-078 (CVE-2026-104714, shared message formatter exposes date/time values across concurrent requests) published; both reported by n0mi1k.
- Bulletin S2-076 published for CVE-2026-104712, a denial of service from disproportionately large responses when rendering BigDecimal request parameters (reporter: 0xCc.zhang).
- Bulletin S2-075 published for CVE-2026-104711, an OGNL injection in the legacy RESTful action mapper that may lead to remote code execution (reporter: LeaveSong).
- Apache Struts 7.4.0 and 6.12.0 are released as General Availability, fixing four vulnerabilities, with the announcement strongly advising all developers to upgrade.
- Cyber Security News reports the four Struts vulnerabilities and states no active exploitation has been reported.
Sources cited for Apache Struts Vulnerabilities Enable Remote Code Execution
- Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks (Cyber Security News)
- Apache Struts S2-075 - OGNL injection in the legacy RESTful action mapper (CVE-2026-104711)
- Apache Struts S2-076 - Disproportionate response size rendering BigDecimal parameters (CVE-2026-104712)
- Apache Struts S2-077 - Unbounded request body read in the REST plugin (CVE-2026-104713)
- Apache Struts S2-078 - Shared message formatter exposes date/time values across concurrent requests (CVE-2026-104714)
- Apache Struts 7.4.0 / 6.12.0 release announcement
- Apache Struts releases
- Apache Struts 2 Security Bulletins index
Detection coverage for TL-2026-2982
As of 2026-10-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2982 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.