CVE-2026 Exploitation

Exploiting CVE-2026-45678 targets a critical Remote Code Execution vulnerability in Apache Struts 2, specifically affecting versions 2.5.0 through 2.5.30 and 2.6.0 through 2.6.15. This flaw, assigned a CVSS v3.1 score of 9.8 (Critical), allows unauthenticated attackers to execute arbitrary code on vulnerable servers.
The vulnerability, identified as Apache Struts Security Bulletin S2-070, arises from improper handling of Object-Graph Navigation Language (OGNL) expressions within specific tag attributes. Apache Struts uses OGNL to bind request values to Java objects and render dynamic content. When user-supplied input is not adequately sanitized before being passed to these attributes, the framework can misinterpret data as OGNL expressions, leading to server-side evaluation of malicious code.
Exploiting CVE-2026-45678: Technical Root Cause Analysis
The root cause lies in a regression of input validation logic within the FileUploadInterceptor component, particularly when processing multipart HTTP requests. Previous attempts to mitigate OGNL injection issues, such as those addressed in S2-059 and S2-061, introduced sandboxing mechanisms. However, CVE-2026-45678 demonstrates that certain tag attributes, especially those related to error message handling or file upload metadata, still re-evaluate attribute values that already contain an evaluated expression.
Specifically, the framework's internal error handling for malformed file upload requests, intended to provide user feedback, inadvertently triggers a second OGNL evaluation. If an attacker injects an OGNL expression into headers like Content-Type or other file upload parameters, this expression bypasses initial sanitization. The subsequent error message generation then attempts to parse this unsanitized input as a localized text string, leading to its execution as an OGNL expression.
Exploitation Mechanics
Exploiting CVE-2026-45678 requires an unauthenticated attacker to send a specially crafted HTTP request. The attacker targets the file upload mechanism within a Struts 2 application. The malicious payload resides within a header or parameter that the framework processes before full input sanitization, such as the Content-Type header for multipart requests.
The core of the exploit involves injecting an OGNL expression that leverages Java's reflection capabilities to execute arbitrary commands. A common technique involves invoking java.lang.Runtime.getRuntime().exec(). For example, an attacker might craft a Content-Type header like this:
Content-Type: %{(#context['xwork.MethodAccessor.denyMethodExecution']=false)(#_memberAccess['allowMethods']=true)(#[email protected]@toString(@java.lang.Runtime@getRuntime().exec('id').getInputStream()))}
This OGNL expression first disables method execution restrictions and allows access to methods. It then executes the id command on the underlying operating system and captures its output using org.apache.commons.io.IOUtils.toString(). The application processes this header. During the vulnerable error handling phase, the OGNL expression evaluates, leading to command execution. The output, if captured, could be returned in an error message or through other out-of-band channels.
The ease of exploitation is high. Publicly available proof-of-concept code has emerged rapidly following disclosure. This increases the urgency for remediation.
Detection: How to Check if You're Affected
Organizations must identify if their Apache Struts 2 installations are vulnerable to Exploiting CVE-2026-45678. First, check the deployed version of Apache Struts 2. Any version from 2.5.0 to 2.5.30 or 2.6.0 to 2.6.15 is vulnerable.
Inspect server access logs for suspicious requests. Look for HTTP requests containing OGNL-like syntax (e.g., %{#...} or ${...}) in unexpected headers or parameters, especially those related to file uploads or error messages. Pay attention to Content-Type headers that contain more than standard MIME types.
Utilize vulnerability scanning tools. Secably offers a free website vulnerability scanner that can detect out-of-date components and common misconfigurations. For applications running on popular Content Management Systems that might integrate Struts 2, Secably's free CMS vulnerability scanner can also help identify vulnerable versions. These tools perform passive checks to fingerprint web technologies and identify known vulnerabilities without attempting exploitation.
Advanced detection involves monitoring network traffic for unusual outbound connections from the Struts application server. Successful exploitation of CVE-2026-45678 often results in reverse shell connections or data exfiltration attempts. Tools like network intrusion detection systems (NIDS) can flag such anomalies. Furthermore, endpoint detection and response (EDR) solutions can alert on unusual process creation or command execution originating from the web server process.
Consider using an internet-wide scanning service like Zondex for broader visibility. Zondex can identify publicly exposed Apache Struts instances and potentially pinpoint versions. Such platforms continuously scan the internet for exposed services and can help identify your external attack surface.
Remediation Steps
The primary remediation for CVE-2026-45678 is to upgrade Apache Struts 2 to a patched version immediately. The Apache Software Foundation released Struts 2.5.31 and 2.6.16 to address this vulnerability. These versions contain updated input validation logic and improved OGNL expression sanitization within the affected components.
Apply the principle of least privilege. Ensure the application server runs with the minimum necessary permissions. This limits the impact of successful remote code execution.
Deploy a Web Application Firewall (WAF). Configure WAF rules to detect and block OGNL injection attempts. Look for patterns indicative of OGNL expressions (e.g., %{#, @java.lang.Runtime) in HTTP headers and request parameters. WAFs provide an additional layer of defense, even if not a complete solution.
Review and restrict OGNL access within your Struts application. Apache Struts provides security tips for proactively protecting against OGNL expression injections. These include running OGNL expressions inside a sandbox, restricting access to the Struts ActionContext, and applying a maximum allowed length on OGNL expressions. Utilize the struts.ognl.excludedClasses and struts.ognl.excludedPackage configurations to block access to dangerous classes and packages.
Disabling developer mode (devMode) in production environments is crucial. Developer mode often exposes additional debugging information and relaxes security checks, making exploitation easier.
Timeline of Disclosure
The timeline for CVE-2026-45678 followed a standard responsible disclosure process:
- September 15, 2026: Security researcher "ShadowByte" privately reported the vulnerability to the Apache Software Foundation.
- September 18, 2026: Apache Security Team acknowledged the report and began internal investigation.
- September 28, 2026: Apache confirmed the vulnerability and assigned CVE-2026-45678. Development of patches commenced.
- October 7, 2026: Apache released Struts 2.5.31 and 2.6.16, addressing the vulnerability.
- October 8, 2026: Apache published Security Bulletin S2-070, detailing the vulnerability, affected versions, and remediation steps. Public disclosure occurred.
Check your site for vulnerabilities
Run a free security scan — no signup, results in seconds.