[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Security advisory: Pre-authentication RCE in Apache Struts 2 2.6.11.0 (Apache Software Foundation)
- To: fulldisclosure@xxxxxxxxxxxx
- Subject: [FD] Security advisory: Pre-authentication RCE in Apache Struts 2 2.6.11.0 (Apache Software Foundation)
- From: disclosure via Fulldisclosure <fulldisclosure@xxxxxxxxxxxx>
- Date: Mon, 3 Aug 2026 03:34:45 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in Apache
Struts 2 2.6.11.0 (Apache Software Foundation). The research is published and a
proof-of-concept is available.
Pre-authentication RCE (CVSS 9.8, pre-authentication)
Apache Struts 2.6.11.0 is vulnerable to unauthenticated remote code execution
under a documented REST mapper configuration combined with wildcard dynamic
dispatch. RestfulActionMapper.getMapping() extracts the action name from the
request URI without calling cleanupActionName, the character-set gate that
DefaultActionMapper adopted after S2-057; that fix was never synchronized to
the REST mapper. When an application uses struts.mapper.class=restful with a
wildcard action and a result containing {1} substitution, attacker-controlled
OGNL metacharacters flow through the wildcard capture into
TextParseUtil.translateVariables, bypassing AcceptedPatternsChecker. A novel
java.beans.Expression/Statement reflection primitive then defeats the
SecurityMemberAccess sandbox and reaches Runtime.exec. The chain was verified
with uid=0(root) on a Tomcat 9 / OGNL 3.3.5 deployment. The only precondition
is an opt-in but documented configuration subset (REST mapper plus wildcard
dynamic dispatch).
Impact: Arbitrary operating system command execution as the JVM process user;
on a root-run deployment, full host compromise. No credentials are required.
Advisory: https://0day-rubbish.com/blog/apache-struts2-restful-mapper-ognl-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/