# Apache Struts Vulnerabilities Enable Remote Code Execution and Denial of Service (CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714)

> The Apache Struts project fixed four vulnerabilities (S2-075 to S2-078) in Struts 7.4.0 and 6.12.0 on 2026-10-02: an OGNL injection in the legacy RESTful action mapper that can lead to remote code execution, a BigDecimal rendering denial of service, an unbounded request body read in the REST plugin, and a shared message formatter that can leak date/time values between concurrent users. No active exploitation or public PoC is reported.

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2982
- **ID:** TL-2026-2982
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-104711, CVE-2026-104712, CVE-2026-104713, CVE-2026-104714

## Description

On 2026-10-02 the Apache Struts project released Struts 7.4.0 and 6.12.0 (both General Availability) and published four security bulletins, S2-075 through S2-078. Cyber Security News covered the disclosure on 2026-10-06. The release announcement strongly advises all developers to upgrade. Struts 7.3.0 and 6.11.0, released 2026-08-01, are the last vulnerable releases in their lines.

CVE-2026-104711 (S2-075, rated Moderate by Apache, reporter LeaveSong) is an OGNL injection in the legacy RESTful action mapper. A crafted request can inject an OGNL expression that may lead to remote code execution. Affected versions are Struts 2.0.0-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0 and 7.0.0-7.3.0. The S2-075 bulletin attaches the condition that the OGNL allowlist is disabled to the 7.x range; the press article states the allowlist-disabled condition more broadly. Applications using the default mapper, the restful2 mapper or the Struts REST plugin are not affected. The only workaround is to switch away from the legacy RESTful action mapper.

CVE-2026-104712 (S2-076, Moderate, reporter 0xCc.zhang) is a resource-exhaustion denial of service. When request parameters bind to java.math.BigDecimal properties and are rendered through Struts tag libraries, small requests can produce responses many orders of magnitude larger. Affected versions are 2.5.14-2.5.33 (EOL), 6.0.0-6.11.0 and 7.0.0-7.3.0. Applications that do not bind BigDecimal properties, that use JSON/REST plugin responses, or that use other numeric types are unaffected. The workaround is a custom BigDecimal type converter registered in struts-conversion.properties (xwork-conversion.properties on 2.5.x) that bounds the scale before rendering.

CVE-2026-104713 (S2-077, Important, reporter n0mi1k) is a memory-exhaustion denial of service. The REST plugin reads a request body into memory with no bound, so oversized requests can exhaust the heap. Affected versions are 2.1.8-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0 and 7.0.0-7.3.0. Struts has no configuration-only fix. The patched releases add a default limit of 2,097,152 characters (2 MB), configurable with struts.rest.content.maxLength. Until upgraded, defenders should enforce a maximum request body size in the reverse proxy or servlet container.

CVE-2026-104714 (S2-078, Moderate, reporter n0mi1k) is a concurrency flaw. A message formatter is shared between concurrently served requests. When localized messages format date or time arguments, one user's value can appear in another user's response, or rendering can fail and surface as a server error. Ordinary concurrent traffic triggers it, with no malicious input needed. Affected versions are 2.0.0-2.3.37, 2.5.0-2.5.33, 6.0.0-6.11.0 and 7.0.0-7.3.0. The workaround is to format date/time values before message interpolation.

The sources state no numeric CVSS score, no active exploitation, no public PoC and no network or file indicators of compromise. Apache's own ratings are Moderate (104711, 104712, 104714) and Important (104713). The HIGH severity assigned here is an analyst estimate based on the remote code execution class of CVE-2026-104711, not a source-stated score. The CVE ids themselves come from the Apache bulletins; NVD and web searches returned nothing for them at the time of research.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1499.003 Application Exhaustion Flood
- T1499.004 Application or System Exploitation

## Sources

- [Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks (Cyber Security News)](https://cybersecuritynews.com/apache-struts-vulnerabilities/)
- [Apache Struts S2-075 - OGNL injection in the legacy RESTful action mapper (CVE-2026-104711)](https://cwiki.apache.org/confluence/display/WW/S2-075)
- [Apache Struts S2-076 - Disproportionate response size rendering BigDecimal parameters (CVE-2026-104712)](https://cwiki.apache.org/confluence/display/WW/S2-076)
- [Apache Struts S2-077 - Unbounded request body read in the REST plugin (CVE-2026-104713)](https://cwiki.apache.org/confluence/display/WW/S2-077)
- [Apache Struts S2-078 - Shared message formatter exposes date/time values across concurrent requests (CVE-2026-104714)](https://cwiki.apache.org/confluence/display/WW/S2-078)
- [Apache Struts 7.4.0 / 6.12.0 release announcement](https://struts.apache.org/announce-2026)
- [Apache Struts releases](https://struts.apache.org/releases.html)
- [Apache Struts 2 Security Bulletins index](https://cwiki.apache.org/confluence/display/WW/Security+Bulletins)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2982
