Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apache Struts 2 OGNL Expression Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A remote code execution vulnerability has been identified in Apache Struts versions 2.0.0 through 2.3.15. This vulnerability allows attackers to execute arbitrary OGNL expressions by sending crafted requests with specific prefixes, such as action:, redirect:, or redirectAction:. The issue arises from inadequate sanitization of user input, enabling the execution of malicious code on the server.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected server.

Reproduction

To reproduce this vulnerability, send a request to the server running an affected version of Apache Struts. Include a parameter with a crafted OGNL expression, using one of the vulnerable prefixes (action:, redirect:, or redirectAction:). The server's response should indicate that the OGNL expression has been executed, demonstrating successful exploitation.

Remediation

Users are advised to upgrade to Apache Struts versions later than 2.3.15. For guidance on updating, consult the Apache Struts documentation.

Added: Mar 16, 2026, 8:18 PM
Updated: Mar 16, 2026, 8:18 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
7.5
exploitability
10.0
remediation
0.0
relevance
0.0
threat
9.9
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.