CVE WATCH / VULNERABILITY DETAIL
CVE-2026-104711
UNKNOWNCVSS 0NVD feed
Published 5 October 2026 · tracked since 6 October 2026
Description
Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote cod
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105644 MEDIUM 6.8
- CVE-2026-105645 MEDIUM 4.9
- CVE-2026-105646 MEDIUM 4.9
- CVE-2026-105712 LOW 3.6
- CVE-2026-105638 CRITICAL 9.1
- CVE-2026-105640 CRITICAL 9.1
- CVE-2026-105641 CRITICAL 9.8
- CVE-2026-105642 HIGH 8.8
- CVE-2026-105643 HIGH 7.3
- CVE-2026-105386 HIGH 7.3