Apache Struts 2.x <= 2.3.37 / 2.5.x <= 2.5.33 / 6.x < 6.12.0 / 7.x < 7.4.0 Multiple Vulnerabilities (S2-075) (S2-078)

critical Nessus Plugin ID 364469

Synopsis

The Apache Struts install on the remote host is affected by multiple vulnerabilities.

Description

The version of Apache Struts installed on the remote host is 2.0.0 through 2.3.37, or 2.5.0 through 2.5.33, or 6.x prior to 6.12.0, or 7.x prior to 7.4.0. It is, therefore, affected by multiple vulnerabilities, as referenced in the S2-075 and S2-078 advisories:

- Improper neutralization of special elements used in an expression language statement ('Expression Language Injection') vulnerability in Apache Struts. If the application is configured to use the legacy RESTful action mapper, a crafted request can inject an OGNL expression that may lead to remote code execution. Struts 7 is affected only when the OGNL allowlist is disabled; it is enabled by default. Applications using the default action mapper, the restful2 mapper, or the Struts REST plugin are not affected. (CVE-2026-104711)

- Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation, so a value belonging to one user can appear in another user's response, or the rendering can fail and surface as a server error. Applications whose localized messages format no date or time arguments are not affected.
(CVE-2026-104714)

Both issues are only exposed by specific application configurations, which Nessus cannot verify, so this finding is flagged as a potential vulnerability.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Apache Struts version 6.12.0 / 7.4.0 or later. Alternatively, apply the workaround as referenced in the vendor's security bulletin.

See Also

https://cwiki.apache.org/confluence/spaces/WW/pages/446070946/S2-075

https://cwiki.apache.org/confluence/spaces/WW/pages/451972217/S2-078

https://struts.apache.org/announce-2026

Plugin Details

Severity: Critical

ID: 364469

File Name: struts_S2-075_S2-078.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 10/9/2026

Updated: 10/9/2026

Configuration: Enable paranoid mode, Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.5

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:apache:struts

Required KB Items: Settings/ParanoidReport

Patch Publication Date: 10/2/2026

Vulnerability Publication Date: 10/5/2026

Reference Information

CVE: CVE-2026-104711, CVE-2026-104714

IAVA: 2026-A-1088