CVE-2026-25866Monday, March 16, 2026

Remote Code Execution in Apache Struts Expression Language Parser

A remote code execution vulnerability exists in Apache Struts versions 2.5.0 through 2.5.30 due to improper validation of OGNL expressions in the expression language parser. An unauthenticated attacker can execute arbitrary code on the target system by submitting specially crafted expressions through HTTP requests.

Not KEV Listed✓ Fix Available
Remote Code Execution in Apache Struts Expression Language Parser
💡

This section explains the vulnerability in everyday language, so anyone can understand the risk and impact.

This security flaw affects Apache Struts, which is software used to build web applications. The vulnerability allows attackers to run malicious code on servers running vulnerable versions of Struts without needing any password or special access.

It's like finding a backdoor that lets someone enter a building and run whatever programs they want on the computers inside, just by sending a specially formatted message to the web server. This is particularly dangerous because attackers don't need to log in or have any special privileges to exploit it.

This vulnerability could let attackers steal data, install malware, or take complete control of the affected web servers.

Affected Products

1affected product identified
ProductVendorVersionPatched
>StrutsApache2.5.0-2.5.302.5.31
🔧

Remediation

Fix Available

1. Upgrade Apache Struts to version 2.5.31 or later

2. If immediate upgrade is not possible, implement WAF rules to filter malicious OGNL expressions

3. Monitor system logs for potential exploitation attempts

4. Review and restrict access to Struts-based applications where possible

CVSS Score
9.8
CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Vector (v3.1)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Quick Info
CVE IDCVE-2026-25866
Severitycritical
FixAvailable
KEVNot Listed
PublishedMar 16, 2026