CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104711

UNKNOWNCVSS 0NVD feed

Published 5 October 2026 · tracked since 6 October 2026

Description

Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote cod

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-104711 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-104711

UNKNOWNCVSS 0NVD feed

Published 5 October 2026 · tracked since 6 October 2026

Description

Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote cod

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]